Follow ZDNET: Add us as a preferred source on Google. Researchers have disclosed WhisperPair, a family of vulnerabilities that impact a protocol commonly used to pair headphones, earbuds, and other audio products with Bluetooth devices. Also: Your Windows PC needs this patch to ward off nasty bootkit malware - update now As first reported by Wired, WhisperPair was uncovered by a team of researchers from Belgium's KU Leuven University, supported by the government's Cybersecurity Research Program. The findings relate to the improper implementation of Google's Fast Pair protocol, which enables one-tap pairing and account synchronization across Bluetooth accessories. If the protocol hasn't been implemented correctly, a security flaw is introduced that "allows an attacker to hijack devices and track victims using Google's Find Hub network," according to the researchers. Also: How this one-click Copilot attack bypassed security controls - and what Microsoft did about it The vulnerability research was reported to Google privately in August 2025 and was issued a critical rating under CVE-2025-36911. A 150-day disclosure window was agreed and a bug bounty of $15,000 was awarded. WhisperPair occurs because many audio accessories skip a "critical step" during Fast Pair pairing. This is how it works: a "seeker" -- such as a Bluetooth-enabled mobile device -- sends a message to the "provider," an audio accessory. The message includes a pairing request. While the Fast Pair protocol specifi...
Check your earbuds ASAP for this flaw that lets attackers spy on you - here's how
ZDNet
·Charlie Osborne
·Published Jan 16, 2026
·Updated
Affected Software
4 affected components
Google Fast Pair<=2025
Sony audio accessories
Harman JBL
Anker audio accessories
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the WhisperPair vulnerability that affects Bluetooth headphones and audio products, posing a risk of unauthorized access.
2
What security implications are discussed in the article?
The vulnerabilities could allow attackers to eavesdrop on conversations through compromised audio devices.
3
Which products are specifically mentioned as being affected by WhisperPair vulnerabilities?
The affected products include Google Fast Pair-enabled devices, Sony audio accessories, Harman JBL speakers, and Anker audio accessories.
4
What should users do in light of these vulnerabilities?
Users are advised to check their Bluetooth audio devices for updates or disable the vulnerable features until patches are available.
5
Who disclosed the WhisperPair vulnerabilities?
The vulnerabilities were disclosed by researchers focusing on security flaws in widely-used Bluetooth pairing protocols.