Critical WhisperPair flaw lets hackers track, eavesdrop via Bluetooth audio devices
ID: ab663b8b-5189-5c8d-80e5-0138e1edf3c0
STIX ID: report--ab663b8b-5189-5c8d-80e5-0138e1edf3c0
Feed Name: Bleeping Computer
Security researchers disclosed a critical vulnerability in the Fast Pair implementation (CVE-2025-36911, "WhisperPair") affecting many Bluetooth headphones, earbuds, and speakers from multiple vendors; attackers can force pairing within ~14 meters to hijack audio devices, eavesdrop via microphones, and enable tracking via Google Find network. Manufacturers have been notified and some firmware patches were released, but updates may not be available for all affected devices and disabling Fast Pair on phones does not mitigate the accessory-side flaw.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
