logo

WhisperPair Vulnerability Allows Attackers to Pair Devices Without User Consent 

ID: c06c53cf-ba6a-51ac-893a-5e3b601835f1

STIX ID: report--c06c53cf-ba6a-51ac-893a-5e3b601835f1

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-01-20

Date Updated: 2026-04-22

Author: Divya

...
...

Researchers disclosed "WhisperPair" (CVE-2025-36911), a critical Fast Pair implementation flaw that lets attackers forcibly pair with and take control of Bluetooth headphones, earbuds, and speakers without user consent—allowing eavesdropping, forced audio playback, and persistent location tracking via abused account keys. The issue affects multiple vendors and chipsets despite passing certification, has a CVSS 9.8 rating, and while some manufacturers have issued patches after responsible disclosure, many devices remain unpatched; users are advised to disable Bluetooth when idle and verify updates with manufacturers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.