Update your Bluetooth headphones now: Google Fast Pair “WhisperPair” bug risks eavesdropping and tracking

Update your Bluetooth headphones now: Google Fast Pair “WhisperPair” bug risks eavesdropping and tracking

January 16, 2026

BRUSSELS, Jan 16, 2026, 10:29 CET

  • Researchers at KU Leuven revealed “WhisperPair” attacks capable of silently taking over certain Fast Pair earbuds, headphones, and speakers
  • The affected devices include major consumer brands, impacting both iPhone and Android users alike
  • These fixes rely on firmware updates from manufacturers, yet many users never actually apply them

Researchers from Belgium’s KU Leuven have revealed a series of attacks dubbed “WhisperPair” targeting vulnerabilities in certain Bluetooth audio devices using Google’s Fast Pair feature. The flaws let attackers nearby connect without permission, hijack audio streams, and sometimes even convert the devices into location-tracking tools. Kuleuven

Researchers revealed to WIRED that they uncovered security flaws in 17 Fast Pair audio devices across 10 brands, such as Sony, Jabra, JBL, Marshall, Xiaomi, Nothing, OnePlus, Soundcore, Logitech, and Google. KU Leuven’s Sayon Duttagupta claimed, “In less than 15 seconds, we can hijack your device.” WIRED

The main issue is straightforward: the patch typically comes as a firmware update via the manufacturer’s app, which many users never install. A Google spokesperson noted the company collaborated with researchers on these fixes and hasn’t observed any real-world exploitation beyond lab settings, but still urged users to keep their firmware up to date.

Fast Pair, launched in 2017, aims to simplify Bluetooth pairing to just a single tap. However, researchers point out that many accessories neglect a fundamental security step—they accept pairing requests even when not in “pairing mode,” which usually requires pressing a button. Since Fast Pair is integrated directly into the accessory, turning off prompts on the phone won’t fix the core problem. Firmware updates remain the primary way to address this vulnerability. Whisperpair

According to tests reported by 9to5Google, attackers can exploit everyday hardware like a laptop or Raspberry Pi to initiate an unauthorized pairing if an accessory bypasses the pairing-mode verification. Victims might only notice an “unwanted tracking” alert afterward, which traces back to their own device. 9to5Google

The vulnerability, documented as CVE-2025-36911, carries a “High” severity rating in the GitHub Advisory Database. It has a CVSS 3.1 score of 7.1 and an “Adjacent” attack vector, indicating that an attacker must be within close proximity, like Bluetooth range, to exploit it. Importantly, no user interaction is needed. GitHub

On Jan. 15, the US National Vulnerability Database released the CVE entry classifying it as an information disclosure flaw. This vulnerability arises from a logic error in “key-based pairing,” potentially revealing users’ conversations and location. NVD

The researchers’ device list identifies certain models as vulnerable, naming Sony’s WH-1000XM6 and WH-1000XM5 headphones, Google’s Pixel Buds Pro 2, JBL’s Tune Beam, Xiaomi’s Redmi Buds 5 Pro, and Nothing’s Ear (a). Meanwhile, other products like Apple’s Beats Solo Buds are marked as not vulnerable in their tests.

It’s still unclear if Google’s software patches for the Find Hub tracking issue really work. Engadget noted that Google pushed a fix to stop tracking misuse through Find Hub, yet researchers quickly uncovered a way around it.

Ars Technica revealed that the bug impacts over a dozen device models spanning 10 manufacturers, including Google’s earbuds. They cautioned that the vulnerability might persist for some time if users and vendors delay applying patches.

Bluetooth devices with Google Fast Pair vulnerable to “WhisperPair” hack
.

Mateusz Brzeziński

Mateusz Brzeziński is a financial and technology journalist at Bez-kabli.pl, covering stocks, artificial intelligence, semiconductors and global market developments. He graduated from the Prague University of Economics and Business in the Czech Republic and previously worked in financial analysis before moving into business journalism. His reporting focuses on the companies, technologies and market trends shaping the global economy.

Stock Market Today

  • Computacenter, Antofagasta shares double over 12 months; focus turns to Ceres Power
    August 13, 2026, 2:14 AM EDT. Computacenter jumped 112.7% and Antofagasta gained 98% in the last year, more than doubling a hypothetical £8,500 stake to almost £17,455. Those returns look tough to repeat for anyone buying in now. Traders are looking at Ceres Power Holdings in the FTSE 250. Forecasts point to 105% upside, but Ceres is still loss-making after a 60% slide in five years. The company has fresh £103m funding for its solid oxide fuel cell plans. Its balance sheet is called strong, and some analysts are cautiously upbeat, though risks around execution are flagged. Past winners show what's possible but don't set a guarantee.