logo

Critical WhisperPair flaw lets hackers track, eavesdrop via Bluetooth audio devices

ID: ab663b8b-5189-5c8d-80e5-0138e1edf3c0

STIX ID: report--ab663b8b-5189-5c8d-80e5-0138e1edf3c0

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-01-15

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Security researchers disclosed a critical vulnerability in the Fast Pair implementation (CVE-2025-36911, "WhisperPair") affecting many Bluetooth headphones, earbuds, and speakers from multiple vendors; attackers can force pairing within ~14 meters to hijack audio devices, eavesdrop via microphones, and enable tracking via Google Find network. Manufacturers have been notified and some firmware patches were released, but updates may not be available for all affected devices and disabling Fast Pair on phones does not mitigate the accessory-side flaw.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.