logo

Fast Pair, loose security: Bluetooth accessories open to silent hijack

ID: 5d4c0a4d-8dd7-506b-8b21-bcd2574e202c

STIX ID: report--5d4c0a4d-8dd7-506b-8b21-bcd2574e202c

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-01-17

Date Updated: 2026-04-26

Author: Carly Page

...
...

Researchers uncovered "WhisperPair," a flaw in Google's Fast Pair implementation where many Bluetooth earbuds, headphones, and speakers accept pairing requests at any time instead of enforcing explicit user-initiated pairing mode. Attackers within Bluetooth range can hijack devices to inject or interrupt audio, manipulate volume, activate microphones, or register devices to receive location updates. Google and some manufacturers are releasing firmware fixes, but coverage is inconsistent and many inexpensive accessories may never be patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.