Google's Fast Pair protocol offers one of the best Bluetooth experiences today, automatically connecting wireless headphones, speakers, and other accessories while sharing those details across your account. However, a new study raises serious security concerns about some Fast Pair devices, requiring individual updates for each device .

Researchers from KU Leuven University in Belgium have published findings on a group of Fast Pair vulnerabilities, which they have dubbed WhisperPair. These vulnerabilities were reported to Google in August 2025 and were rated critical. While most users may not be at immediate risk, understanding how they work is important.
See also: Hackers exploit Google Cloud and steal Microsoft 365 login credentials
Fast Pair: How do WhisperPair vulnerabilities work?
The WhisperPair vulnerabilities allow attackers to use any Bluetooth-enabled device—like a laptop or Raspberry Pi—to target a vulnerable device, , remotely connectingwithout physical interaction, to your phone or headphones. The security issue arises from accessories that skip a critical part of the connection process: detecting whether the product is actively in pairing mode.
If this control is absent from the product software, hackers can remotely initiate the connection and users may only be notified via a potential “unwanted tracking” alert, misleadingly indicating their own device as the source.
See also: Phishing campaign abuses Google Cloud email feature

To initiate Fast Pair, a Seeker (a phone) sends a message to the Provider (an accessory) indicating a desire to connect. The Fast Pair specification states thatif the accessory is not in pairing mode, it should ignore such messages. However, many devices do not enforce this check, allowing unauthorized devices to initiate the connection process.
After receiving a response from the vulnerable device, an attacker can complete the Fast Pair process by establishing a regular Bluetooth connection.
Risks of breach
Not all Fast Pair accessories are vulnerable to these methods, but those that are vulnerable offer potential hackers a lot of potential. The risks include location tracking via Find Hub, interrupting audio playback , and recording phone calls and surroundings. These threats affect both Android and iOS, as the Fast Pair-enabled accessory is the one being targeted, not the specific phone.
See also: Android malware Cellik creates malicious versions of Google Play apps

Some products affected by the WhisperPair vulnerabilities include the Sony WH-1000XM6 headphones, along with their predecessors, the XM5s and XM4s, as well as Sony's Ear(a)Nothing headphones, the OnePlus Nord Buds 3 Pro, and Google's Pixel Buds Pro 2 .
For more details, the official WhisperPair website and a detailed report from Wired provide further information. The researchers recommend keeping accessories that support Fast Pair updated, as there is no way for end users to disable this functionality themselves.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
