Follow ZDNET: Add us as a preferred source on Google. Researchers have disclosed WhisperPair, a family of vulnerabilities that impact a protocol commonly used to pair headphones, earbuds, and other audio products with Bluetooth devices. Also: Your Windows PC needs this patch to ward off nasty bootkit malware - update now As first reported by Wired, WhisperPair was uncovered by a team of researchers from Belgium's KU Leuven University, supported by the government's Cybersecurity Research Program. The findings relate to the improper implementation of Google's Fast Pair protocol, which enables one-tap pairing and account synchronization across Bluetooth accessories. If the protocol hasn't been implemented correctly, a security flaw is introduced that "allows an attacker to hijack devices and track victims using Google's Find Hub network," according to the researchers. Also: How this one-click Copilot attack bypassed security controls - and what Microsoft did about it The vulnerability research was reported to Google privately in August 2025 and was issued a critical rating under CVE-2025-36911. A 150-day disclosure window was agreed and a bug bounty of $15,000 was awarded. WhisperPair occurs because many audio accessories skip a "critical step" during Fast Pair pairing. This is how it works: a "seeker" -- such as a Bluetooth-enabled mobile device -- sends a message to the "provider," an audio accessory. The message includes a pairing request. While the Fast Pair protocol specifi...
A new earbud security flaw may expose you to remote eavesdropping - here's how to fix it
ZDNet
·Charlie Osborne
·Published Jan 17, 2026
·Updated
Affected Software
4 affected components
Google Fast Pair<latest
Sony Bluetooth audio accessories<latest
Harman JBL audio accessories<latest
Anker Bluetooth audio accessories<latest
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the WhisperPair vulnerabilities affecting Bluetooth pairing protocols for audio devices.
2
What security implications are discussed?
The vulnerabilities may allow attackers to remotely eavesdrop on conversations through compromised Bluetooth headphones and earbuds.
3
Which products or software are affected by the vulnerabilities?
Affected products include Google Fast Pair, Sony Bluetooth audio accessories, Harman JBL audio accessories, and Anker Bluetooth audio accessories.
4
How can users protect themselves from this vulnerability?
Users are advised to update their devices to the latest firmware to mitigate the security risks.
5
Who disclosed the WhisperPair vulnerabilities?
The vulnerabilities were disclosed by security researchers focusing on Bluetooth pairing security.