HomeSecurityGoogle Fast Pair: Vulnerabilities allow attackers to track you

Google Fast Pair: Vulnerabilities allow attackers to track you

Google's Fast Pair protocol offers one of the best Bluetooth experiences today, automatically connecting wireless headphones, speakers, and other accessories while sharing those details across your account. However, a new study raises serious security concerns about some Fast Pair devices, requiring individual updates for each device .

Google Fast Pair

Researchers from KU Leuven University in Belgium have published findings on a group of Fast Pair vulnerabilities, which they have dubbed WhisperPair. These vulnerabilities were reported to Google in August 2025 and were rated critical. While most users may not be at immediate risk, understanding how they work is important.

See also: Hackers exploit Google Cloud and steal Microsoft 365 login credentials

Fast Pair: How do WhisperPair vulnerabilities work?

The WhisperPair vulnerabilities allow attackers to use any Bluetooth-enabled device—like a laptop or Raspberry Pi—to target a vulnerable device, , remotely connectingwithout physical interaction, to your phone or headphones. The security issue arises from accessories that skip a critical part of the connection process: detecting whether the product is actively in pairing mode.

If this control is absent from the product software, hackers can remotely initiate the connection and users may only be notified via a potential “unwanted tracking” alert, misleadingly indicating their own device as the source.

See also: Phishing campaign abuses Google Cloud email feature

Google Fast Pair: Vulnerabilities allow attackers to track you

To initiate Fast Pair, a Seeker (a phone) sends a message to the Provider (an accessory) indicating a desire to connect. The Fast Pair specification states thatif the accessory is not in pairing mode, it should ignore such messages. However, many devices do not enforce this check, allowing unauthorized devices to initiate the connection process.

After receiving a response from the vulnerable device, an attacker can complete the Fast Pair process by establishing a regular Bluetooth connection.

Risks of breach

Not all Fast Pair accessories are vulnerable to these methods, but those that are vulnerable offer potential hackers a lot of potential. The risks include location tracking via Find Hub, interrupting audio playback , and recording phone calls and surroundings. These threats affect both Android and iOS, as the Fast Pair-enabled accessory is the one being targeted, not the specific phone.

See also: Android malware Cellik creates malicious versions of Google Play apps

Google Fast Pair: Vulnerabilities allow attackers to track you

Some products affected by the WhisperPair vulnerabilities include the Sony WH-1000XM6 headphones, along with their predecessors, the XM5s and XM4s, as well as Sony's Ear(a)Nothing headphones, the OnePlus Nord Buds 3 Pro, and Google's Pixel Buds Pro 2 .

For more details, the official WhisperPair website and a detailed report from Wired provide further information. The researchers recommend keeping accessories that support Fast Pair updated, as there is no way for end users to disable this functionality themselves.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS