• News/
  • https://www.zdnet.com/article/whisperpair-vulnerability-google-fast-pair-bluetooth-headphones-attack/

Check your earbuds ASAP for this flaw that lets attackers spy on you - here's how

ZDNet
·
Charlie Osborne
·
Published Jan 16, 2026
·
Updated

Follow ZDNET: Add us as a preferred source on Google. Researchers have disclosed WhisperPair, a family of vulnerabilities that impact a protocol commonly used to pair headphones, earbuds, and other audio products with Bluetooth devices. Also: Your Windows PC needs this patch to ward off nasty bootkit malware - update now As first reported by Wired, WhisperPair was uncovered by a team of researchers from Belgium's KU Leuven University, supported by the government's Cybersecurity Research Program. The findings relate to the improper implementation of Google's Fast Pair protocol, which enables one-tap pairing and account synchronization across Bluetooth accessories. If the protocol hasn't been implemented correctly, a security flaw is introduced that "allows an attacker to hijack devices and track victims using Google's Find Hub network," according to the researchers. Also: How this one-click Copilot attack bypassed security controls - and what Microsoft did about it The vulnerability research was reported to Google privately in August 2025 and was issued a critical rating under CVE-2025-36911. A 150-day disclosure window was agreed and a bug bounty of $15,000 was awarded. WhisperPair occurs because many audio accessories skip a "critical step" during Fast Pair pairing. This is how it works: a "seeker" -- such as a Bluetooth-enabled mobile device -- sends a message to the "provider," an audio accessory. The message includes a pairing request. While the Fast Pair protocol specifi...

Read full article

Affected Software

4 affected components
Google Fast Pair<=2025
Sony audio accessories
Harman JBL
Anker audio accessories
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the WhisperPair vulnerability that affects Bluetooth headphones and audio products, posing a risk of unauthorized access.

2

What security implications are discussed in the article?

The vulnerabilities could allow attackers to eavesdrop on conversations through compromised audio devices.

3

Which products are specifically mentioned as being affected by WhisperPair vulnerabilities?

The affected products include Google Fast Pair-enabled devices, Sony audio accessories, Harman JBL speakers, and Anker audio accessories.

4

What should users do in light of these vulnerabilities?

Users are advised to check their Bluetooth audio devices for updates or disable the vulnerable features until patches are available.

5

Who disclosed the WhisperPair vulnerabilities?

The vulnerabilities were disclosed by researchers focusing on security flaws in widely-used Bluetooth pairing protocols.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203