A newly disclosed vulnerability, dubbed 'WhisperPair,' threatens the security of 17 audio devices using Google's Fast Pair technology, potentially enabling attackers to eavesdrop on users. Researchers at KU Leuven University's Computer Security and Industrial Cryptography group discovered the flaw, which stems from improper implementations of the Fast Pair protocol by Google's hardware partners. This vulnerability, if exploited, could allow unauthorized access to device microphones, audio injection, and even location tracking.
Fast Pair's Faulty Foundation
The core issue lies in the circumvention of Fast Pair's intended security measures. Fast Pair is designed to allow new connections only when the audio device is actively in pairing mode, but a design flaw in some implementations allows a threat actor to pair with a device even after it has already been connected to a user's device. Sayon Duttagupta, a researcher at KU Leuven, explained to Wired how easily an attack can be executed: "You're walking down the street with your headphones on, you're listening to some music. In less than 15 seconds, we can hijack your device...Which means that I can turn on the microphone and listen to your ambient sound. I can inject audio. I can track your location."
This attack requires the attacker to be within Bluetooth range and possess the device model number – information that is often easily accessible. Google acknowledges the issue stems from improper implementation of Fast Pair by some of its partners and has been working on mitigations since the vulnerability was reported in August 2025. Google stated to Engadget, that the company provided its OEM partners with recommended fixes in September. Google also updated its Validator certification tool and its certification requirements.
Impact and Mitigation
The implications of WhisperPair extend beyond simple eavesdropping. If an audio accessory has never been paired with a Google account, a hacker could potentially link it to their own, leveraging Google's Find Hub tool for location tracking. While Google claims to have rolled out a fix for this specific scenario, the researchers at KU Leuven assert they quickly found a workaround.
The affected devices span a range of manufacturers, including Sony, Jabra, JBL, Marshall, Xiaomi, Nothing, OnePlus, Soundcore, Logitech and even Google's own Pixel Buds (though these are reportedly already patched). The researchers have released a tool to check if a device is vulnerable. OnePlus stated they are investigating the issue and will "take appropriate action to protect our users' security and privacy."
"The attack surface presented by Bluetooth devices is often underestimated, and WhisperPair is a stark reminder of the potential privacy risks inherent in these technologies."
— Dr. Maya Okonkwo, Automatica PressWhile Google asserts the steps required for a successful attack are complex and require the attacker to remain within Bluetooth range, the relative ease of exploitation is still concerning. As always, users are advised to keep their audio devices updated with the latest firmware. This highlights a broader problem: many users do not install the necessary manufacturer apps to receive these updates, leaving them perpetually vulnerable. The absence of a CVE ID at this time does not diminish the severity of the risk, and I strongly advise all users of Fast Pair enabled devices to vigilantly monitor their vendors for pending security updates. The attack surface presented by Bluetooth devices is often underestimated, and WhisperPair is a stark reminder of the potential privacy risks inherent in these technologies. Further independent audits of Fast Pair and similar protocols are clearly warranted.