Researchers at KU Leuven disclosed WhisperPair, a set of Bluetooth attacks against flawed implementations of Google’s Fast Pair protocol in headphones, earbuds, and speakers from multiple vendors, including Sony, Anker, Nothing, and others. The vulnerabilities can allow an attacker within Bluetooth range to silently pair with a target device, play audio, intercept calls, and activate built-in microphones for eavesdropping. Reporting on the disclosure said the issue affects audio accessories that rely on Fast Pair and stems from vendor implementation weaknesses rather than confirmed abuse in the wild.
In the most serious cases, affecting five Sony models and Google Pixel Buds Pro 2, researchers said an attacker could bind a device to their own Google account and misuse Google’s Find Hub network to track a victim’s location if the accessory had not already been linked to an Android device and Google account. Google said it coordinated with the researchers, issued remediation guidance to accessory makers in September 2025, and tightened certification requirements, while vendors reported patches released, under testing, or planned through OTA firmware updates. Researchers also said they quickly bypassed an added Find Hub mitigation, though Google said that bypass depended on outdated firmware and remains under investigation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Following disclosure, several affected manufacturers said fixes had already been released, were in testing, or were planned for delivery through OTA firmware updates. Because Fast Pair cannot be disabled, users depend on vendor updates for protection.
The researchers said they bypassed an additional Find Hub mitigation within hours of testing it. Google responded that the bypass depended on outdated accessory firmware and said it was investigating the issue.
Researchers from KU Leuven University disclosed a set of Bluetooth attacks dubbed WhisperPair affecting improper implementations of Google's Fast Pair protocol in audio devices from vendors including Sony, Anker, and Nothing. The flaws could allow nearby attackers to secretly pair with devices, play audio, intercept calls, use microphones for eavesdropping, and in some cases bind devices to their own Google account for tracking via Google's Find Hub.
Google said it worked with KU Leuven researchers and sent recommended fixes to affected accessory OEMs in September 2025. It also updated Fast Pair certification requirements in response to the issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcepcgamer.com
Open sourcetheverge.com
Open sourcecybernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.