{"id":9991,"date":"2026-01-20T10:03:41","date_gmt":"2026-01-20T10:03:41","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/20\/whisperpair-attack-allows-hijacking-of-laptops-earbuds-without-user-consent-millions-affected\/"},"modified":"2026-01-20T10:03:41","modified_gmt":"2026-01-20T10:03:41","slug":"whisperpair-attack-allows-hijacking-of-laptops-earbuds-without-user-consent-millions-affected","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/20\/whisperpair-attack-allows-hijacking-of-laptops-earbuds-without-user-consent-millions-affected\/","title":{"rendered":"WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent \u2013 Millions Affected"},"content":{"rendered":"<p>    WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent \u2013 Millions Affected<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p> A critical vulnerability in Google\u2019s Fast Pair protocol that allows attackers to hijack Bluetooth audio accessories and track users without their knowledge or consent.\u200b<\/p>\n<p>Security researchers from KU Leuven have uncovered a vulnerability, tracked as CVE-2025-36911 and dubbed WhisperPair, that affects hundreds of millions of wireless earbuds, headphones, and speakers from major manufacturers.<\/p>\n<p>Including Sony, Anker, Google, Jabra, JBL, Logitech, Marshall, Nothing, OnePlus, Soundcore, and Xiaomi.<\/p>\n<p>Google classified the issue as critical and awarded the researchers the maximum possible bounty of $15,000.\u200b The flaw stems from the improper implementation of the <a href=\"https:\/\/cybersecuritynews.com\/realtek-vulnerability-let-attackers-trigger-dos-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Fast Pair protocol<\/a>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-critical-flaw-in-fast-pair-implementation\"><strong>Critical Flaw in Fast Pair Implementation<\/strong><\/h2>\n<p>According to the Fast Pair specification, Bluetooth accessories should ignore pairing requests when not in pairing mode.<\/p>\n<p>However, many flagship devices fail to enforce this critical security check, allowing unauthorized devices to initiate the pairing process without user interaction.\u200b<\/p>\n<p>Attackers can exploit WhisperPair using any standard Bluetooth-capable device such as a laptop, smartphone, or <a href=\"https:\/\/cybersecuritynews.com\/raspberry-pi-5\/\" target=\"_blank\" rel=\"noreferrer noopener\">Raspberry Pi.<\/a><\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEit3w3P0mPdKwNPqntTZ6DQJR9KEvKKbtUPHiktetwkeGhSzC2Y24OGd8EWDTaBwcm0AJeDFQ-bCNhHgC0ElAuv9vx-4-2ZeD4p2Nolut9JBCyz6v_XuPW2QJ8QEx2X7DuEj_AHBil1OkObkv3S0EVyqi3AaUpW1BTau3e9V2k9vPy3Klp4eGEP_0SHV-I\/s1600\/Screenshot%25202026-01-20%2520105824%2520%25281%2529.webp?ssl=1\" alt=\"Attacker's dashboard with location from the Find Hub network (source : whisperpair )\"><figcaption class=\"wp-element-caption\">Attacker\u2019s dashboard with location from the Find Hub network (source: whisperpair )<\/figcaption><\/figure>\n<\/div>\n<p>The attack succeeds within a median of 10 seconds at ranges up to 14 meters without requiring physical access to the vulnerable device.<\/p>\n<p>Once paired, attackers gain complete control over the audio accessory, enabling them to play audio at high volumes or record conversations through the built-in microphone.\u200b<\/p>\n<p>Additionally, if an accessory has never been paired with an Android device, attackers can add it to their own Google account and track the victim\u2019s location using <a href=\"https:\/\/cybersecuritynews.com\/gemini-deep-research-tool-gmail\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google\u2019s<\/a> Find Hub network.<\/p>\n<p>The tracking notification that appears shows the victim\u2019s own device, which may lead users to dismiss the warning as a <a href=\"https:\/\/cybersecuritynews.com\/critical-bugs-in-ethernet-ip-stack\/\" target=\"_blank\" rel=\"noreferrer noopener\">system bug<\/a>, allowing prolonged surveillance.\u200b<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgmt0MjaNNv6JmekLSsNB9YYrql6GYo0Rzv8ueIDDtT-bZbL0aBb_sLyGJFiG8zbsrgdkA33IksqIihmnOWEzZFU5coEKJyvaolZ24t5XA8Y64UgjiDZkNgNjnIUqW3A2DSGRf-iBXKSd8BOK1eipFws3HL54M0puwAVS_8Ur6ycGeFunwmivyPsGxeN1w\/s1600\/Screenshot%25202026-01-20%2520105844%2520%25281%2529.webp?ssl=1\" alt=\"Unwanted tracking notification showing the victim's own device (source : whisperpair )\"><figcaption class=\"wp-element-caption\">Unwanted tracking notification showing the victim\u2019s own device (source: whisperpair )<\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading\" id=\"h-cross-platform-vulnerability\"><strong>Cross-Platform Vulnerability<\/strong><\/h2>\n<p>The vulnerability affects users across all platforms because the flaw exists in the accessories themselves, not in smartphones.<\/p>\n<p>iPhone users with vulnerable Bluetooth devices face the same risks as Android users. Since Fast Pair functionality cannot be disabled on accessories, even users outside the Android ecosystem remain vulnerable.\u200b<\/p>\n<p>The WhisperPair researchers <a href=\"https:\/\/whisperpair.eu\/#bluetooth-hijacking\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reported<\/a> their findings to Google in August 2025, agreeing to a 150-day disclosure window for manufacturers to release security patches.<\/p>\n<p>The only effective mitigation is installing firmware updates from device manufacturers.<\/p>\n<p>While many manufacturers have released patches, software updates may not yet be available for all vulnerable devices.<\/p>\n<p>Users should consult their accessory\u2019s manual for firmware update instructions and verify patch availability directly with manufacturers.\u200b<\/p>\n<p>The WhisperPair vulnerability represents a systemic failure, as vulnerable devices passed both manufacturer quality assurance and Google\u2019s certification process before reaching the market at scale.\u200b<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/whisperpair-attack\/\">WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent \u2013 Millions Affected<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/whisperpair-attack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent \u2013 Millions Affected A critical vulnerability in Google\u2019s Fast Pair protocol that allows attackers to hijack Bluetooth audio accessories and track users without their knowledge or consent.\u200b Security researchers from KU Leuven have uncovered a vulnerability, tracked as CVE-2025-36911 and dubbed WhisperPair, that affects hundreds [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2240,129,63,163,648],"tags":[130],"class_list":["post-9991","post","type-post","status-publish","format-standard","hentry","category-bluetooth","category-cyber-security","category-cyber-security-news","category-google","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9991"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9991"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9991\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9991"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9991"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9991"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}