• News/
  • https://www.zdnet.com/article/whisperpair-google-fast-pair-bluetooth-headphones-attack/

A new earbud security flaw may expose you to remote eavesdropping - here's how to fix it

ZDNet
·
Charlie Osborne
·
Published Jan 17, 2026
·
Updated

Follow ZDNET: Add us as a preferred source on Google. Researchers have disclosed WhisperPair, a family of vulnerabilities that impact a protocol commonly used to pair headphones, earbuds, and other audio products with Bluetooth devices. Also: Your Windows PC needs this patch to ward off nasty bootkit malware - update now As first reported by Wired, WhisperPair was uncovered by a team of researchers from Belgium's KU Leuven University, supported by the government's Cybersecurity Research Program. The findings relate to the improper implementation of Google's Fast Pair protocol, which enables one-tap pairing and account synchronization across Bluetooth accessories. If the protocol hasn't been implemented correctly, a security flaw is introduced that "allows an attacker to hijack devices and track victims using Google's Find Hub network," according to the researchers. Also: How this one-click Copilot attack bypassed security controls - and what Microsoft did about it The vulnerability research was reported to Google privately in August 2025 and was issued a critical rating under CVE-2025-36911. A 150-day disclosure window was agreed and a bug bounty of $15,000 was awarded. WhisperPair occurs because many audio accessories skip a "critical step" during Fast Pair pairing. This is how it works: a "seeker" -- such as a Bluetooth-enabled mobile device -- sends a message to the "provider," an audio accessory. The message includes a pairing request. While the Fast Pair protocol specifi...

Read full article

Affected Software

4 affected components
Google Fast Pair<latest
Sony Bluetooth audio accessories<latest
Harman JBL audio accessories<latest
Anker Bluetooth audio accessories<latest
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the WhisperPair vulnerabilities affecting Bluetooth pairing protocols for audio devices.

2

What security implications are discussed?

The vulnerabilities may allow attackers to remotely eavesdrop on conversations through compromised Bluetooth headphones and earbuds.

3

Which products or software are affected by the vulnerabilities?

Affected products include Google Fast Pair, Sony Bluetooth audio accessories, Harman JBL audio accessories, and Anker Bluetooth audio accessories.

4

How can users protect themselves from this vulnerability?

Users are advised to update their devices to the latest firmware to mitigate the security risks.

5

Who disclosed the WhisperPair vulnerabilities?

The vulnerabilities were disclosed by security researchers focusing on Bluetooth pairing security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203