Fast Pair, loose security: Bluetooth accessories open to silent hijack
ID: 5d4c0a4d-8dd7-506b-8b21-bcd2574e202c
STIX ID: report--5d4c0a4d-8dd7-506b-8b21-bcd2574e202c
Feed Name: The Register (Security)
Researchers uncovered "WhisperPair," a flaw in Google's Fast Pair implementation where many Bluetooth earbuds, headphones, and speakers accept pairing requests at any time instead of enforcing explicit user-initiated pairing mode. Attackers within Bluetooth range can hijack devices to inject or interrupt audio, manipulate volume, activate microphones, or register devices to receive location updates. Google and some manufacturers are releasing firmware fixes, but coverage is inconsistent and many inexpensive accessories may never be patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
