• News/
  • https://www.zdnet.com/article/whisperpair-google-fast-pair-bluetooth-earbuds-attack/

Your Bluetooth earbuds are at risk of being hijacked - here's how to prevent it ASAP

ZDNet
·
Charlie Osborne
·
Published Jan 20, 2026
·
Updated

Follow ZDNET: Add us as a preferred source on Google. Researchers have disclosed WhisperPair, a family of vulnerabilities that impact a protocol commonly used to pair headphones, earbuds, and other audio products with Bluetooth devices. Also: Your Windows PC needs this patch to ward off nasty bootkit malware - update now As first reported by Wired, WhisperPair was uncovered by a team of researchers from Belgium's KU Leuven University, supported by the government's Cybersecurity Research Program. The findings relate to the improper implementation of Google's Fast Pair protocol, which enables one-tap pairing and account synchronization across Bluetooth accessories. If the protocol hasn't been implemented correctly, a security flaw is introduced that "allows an attacker to hijack devices and track victims using Google's Find Hub network," according to the researchers. Also: How this one-click Copilot attack bypassed security controls - and what Microsoft did about it The vulnerability research was reported to Google privately in August 2025 and was issued a critical rating under CVE-2025-36911. A 150-day disclosure window was agreed and a bug bounty of $15,000 was awarded. WhisperPair occurs because many audio accessories skip a "critical step" during Fast Pair pairing. This is how it works: a "seeker" -- such as a Bluetooth-enabled mobile device -- sends a message to the "provider," an audio accessory. The message includes a pairing request. While the Fast Pair protocol specifi...

Read full article

Affected Software

6 affected components
Google Fast Pair
Google Audio Accessories
Sony audio accessories
Harman Audio Accessories
JBL Audio Accessories
Anker audio accessories
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is WhisperPair?

WhisperPair is a family of vulnerabilities that affect the Bluetooth pairing protocol used by various audio products.

2

What devices are impacted by the vulnerabilities discussed in the article?

Devices impacted include those utilizing Google Fast Pair and other audio accessories from brands like Sony, Harman, JBL, and Anker.

3

What security risks do the WhisperPair vulnerabilities pose?

These vulnerabilities could allow unauthorized users to hijack Bluetooth earbuds and other audio devices.

4

How can users protect their Bluetooth audio devices from WhisperPair vulnerabilities?

Users should ensure their devices are updated with the latest firmware and avoid pairing with unknown devices.

5

Who disclosed the WhisperPair vulnerabilities?

The vulnerabilities were disclosed by security researchers who highlighted the potential risks associated with Bluetooth audio device pairing.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203