Security researchers from KU Leuven disclosed a critical weakness in Google’s Fast Pair Bluetooth pairing protocol implementation—tracked as CVE-2025-36911 and dubbed WhisperPair—that enables attackers to forcibly initiate pairing with vulnerable Bluetooth audio accessories even when they are not in pairing mode. Because the flaw is in the accessories’ Fast Pair behavior (not the phone OS), it can affect users across platforms, including iPhone users, and could be exploited using common Bluetooth-capable hardware (e.g., laptops, phones, or small single-board computers) to hijack connections, track users, and potentially eavesdrop via compromised headphones/earbuds/speakers from multiple vendors.
Reporting indicates the root cause is widespread failure to enforce a key Fast Pair requirement: accessories should ignore pairing requests unless explicitly in pairing mode, but many products respond anyway, allowing an attacker to complete a standard Bluetooth pairing without user awareness. The disclosures also raised questions about Google’s certification pipeline: devices tested by the researchers were reportedly Fast Pair certified, implying they passed Google’s Validator App checks and additional lab testing, yet still exhibited the vulnerable behavior; Google said it has since added new tests focused on these requirements. Responsibility remains unclear between device manufacturers and chipset suppliers; WIRED notes multiple chipset vendors were contacted without comment, while Xiaomi attributed the issue to a “non-standard configuration” by chip suppliers (with Airoha identified as the chipset maker in at least one vulnerable product cited by the researchers).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Researchers released WPair, an Android tool for detecting and demonstrating CVE-2025-36911 on Fast Pair devices. The app includes scanning, non-invasive patch-status testing, and an exploit demonstration for authorized security assessment.
On January 15, 2026, KU Leuven researchers publicly disclosed WhisperPair, describing how many Google Fast Pair audio accessories improperly accept pairing requests when not in pairing mode. They published technical details, impact scenarios including hijacking, eavesdropping, and Find Hub tracking, and a searchable list of affected devices.
Following the researchers' report, Google updated its Fast Pair Validator App and related certification testing with new implementation checks intended to catch the reported flaws. Researchers argued the broader architectural weakness still required stronger protocol-level protections.
During the coordinated disclosure period, multiple vendors began issuing software or firmware updates to address the specific WhisperPair implementation flaws in affected headphones, earbuds, and speakers. Patch availability varied by brand and model, and some devices remained unpatched.
After the private report, Google coordinated a roughly 150-day disclosure window with affected manufacturers so they could prepare firmware fixes for vulnerable Fast Pair audio accessories. The issue was treated as accessory-side, requiring vendor updates rather than phone-only mitigations.
Researchers from KU Leuven disclosed a family of Fast Pair implementation flaws to Google in August 2025. Google assigned CVE-2025-36911, rated the issue critical, and later awarded the team a $15,000 bug bounty.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcezdnet.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcebleepingcomputer.com
Open sourcewired.com
Open sourcewhisperpair.eu
Open sourcemacworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.