WhisperPair: when Bluetooth convenience becomes a security problem
Google Fast Pair was created to simplify pairing Bluetooth accessories. Once a user opens the earbuds' case near a phone, the system offers quick one-tap pairing. Part of this process is linking the device to a Google account and, for some products, the ability to locate them later via the Find Hub network.

Wireless headphones are taken for granted today. They are small, unobtrusive and we mostly only think about them when the battery runs out. That's exactly why the vulnerability called WhisperPair is so troubling. This is not an exotic attack on a fringe device, but a problem that affects the commonly used technology Google Fast Pair and potentially impacts millions of users.
It's important to say right away what WhisperPair is not. It is not a bug in Android itself, it is not a break of Bluetooth encryption, and it is not a universal vulnerability of all headphones. It is a systematic implementation error in Fast Pair by some manufacturers that arose from a combination of convenience, sloppy adherence to the specification, and a failure in the certification process.
How Google Fast Pair is supposed to work
Google Fast Pair was created to simplify pairing Bluetooth accessories. Once a user opens the earbuds' case near a phone, the system offers quick one-tap pairing. Part of this process is linking the device to a Google account and, for some products, the ability to locate them later via the Find Hub network.
The Fast Pair specification contains a clear security rule: if the accessory is not in pairing mode, it must ignore attempts to initiate the Fast Pair process. It is precisely this step that many devices fail to check in practice.
What WhisperPair consists of
Researchers found that for some headphones it's possible to initiate the Fast Pair process even when the user is not performing any pairing. An attacker within Bluetooth range can send a request that the device responds to, and then complete a regular Bluetooth pairing.
This is not a theoretical scenario. Tests show the attack can be carried out in a matter of seconds, without physical access to the headphones and with commonly available hardware. Crucially, however, the attack does not work on all devices – it only affects those that implemented Fast Pair incorrectly.
What an attacker can actually gain
After taking over the headphones, the attacker gains control of the device. In practice, this means the ability to connect to them, disconnect them from the original user, or play audio. On some devices access to the headphones' microphone may also be present, which is why the media report the term "eavesdropping".
For accuracy it's important to be cautious. WhisperPair itself is not a universal tool for secretly recording conversations. The ability to misuse the microphone depends on the specific hardware and how the manufacturer handles audio profiles. Still, it is an intrusion into the integrity of a device that should be fully under the user's control.
Tracking via Find Hub: the less visible part of the problem
The second part of WhisperPair concerns devices that support the Find Hub network. It works similarly to other crowdsourced systems – the location of a lost accessory is estimated using nearby Android devices.
However, if the headphones have never been paired with an Android phone, the so-called Owner Account Key is not set. The first account to write this key to the device is considered the owner. In practice this means that if an attacker adds the device to their Google account before the legitimate user does, they may gain the ability to locate it.
This does not mean continuous real-time tracking, but repeated location records that can indirectly reveal the user's movements. Alerts about unwanted tracking may appear, but they often display the victim's own device location, which leads to the mistaken impression that it is a system bug.
Why this isn't the failure of a single manufacturer
WhisperPair is particularly problematic because it does not concern a single brand. The vulnerable devices passed manufacturers' internal testing as well as Fast Pair certification by Google. This points to a failure of the entire chain, not an individual.
It's a typical example of a situation where a small improvement in user convenience creates a security weakness with an outsized impact.
Responsible disclosure and fixes
The vulnerability was reported to Google in August 2025 and was classified as critical under CVE-2025-36911. During the agreed period, manufacturers had the opportunity to prepare fixes.
One crucial thing: the fix is not on the phone, but in the headphones' firmware. That means the availability of an update depends entirely on the manufacturer of the specific device. Some headphones have already received the fix, others do not yet have it available, and older models may never get it.
What to take away from WhisperPair
WhisperPair is not proof that we should fear all Bluetooth devices. It is, however, a clear reminder that even small and seemingly passive accessories are full-fledged computers with their own logic, memory and identity.
If you use wireless headphones, it makes sense to watch for firmware updates and treat them with the same seriousness as updates to your phone or computer. In this case it's not just a technical detail, but about control over a device you literally keep next to your head all the time.