Kishaan Gidda

Writing · 01

Your earbuds
are not private.

Right now, hundreds of millions of Bluetooth headphones and earbuds that support Google's Fast Pair may be vulnerable to silent hijacking in seconds.

Inside the WhisperPair attack

What WhisperPair is

WhisperPair is a script-based attack that uses a single, versatile script capable of targeting a wide range of Fast Pair-enabled Bluetooth devices. The attack exploits a flaw in how Bluetooth devices implement Google Fast Pair, a protocol designed to make Bluetooth pairing easier and faster for Android devices.

Who's at risk, and why it's a problem

Although Fast Pair is designed to improve pairing on Android devices, iOS users are also at risk, because the vulnerability lies in the accessory itself rather than in the phone.

Under normal circumstances, Fast Pair devices should ignore pairing and interaction requests unless they are explicitly in pairing mode. Many devices fail to enforce that restriction. Researchers at KU Leuven University discovered that this allows unauthorized devices to interact with them even when pairing mode is not enabled, which lets an attacker:

  • Hijack the device without alerting the user
  • Control the audio device's functions, such as playing audio or changing the volume
  • Access the built-in microphones to eavesdrop on conversations
  • Track the user's location by linking the device to a Google account the attacker controls; if this happens, you may receive notifications that you're being tracked by your own device

What devices are affected

Many popular Bluetooth accessories from major brands may be vulnerable if their firmware doesn't properly follow the Fast Pair specification. To check whether your headphones are affected, search for your device at whisperpair.eu/vulnerable-devices. Be mindful that only devices tested so far are listed, which may not include yours.

How to protect yourself

The researchers have not released the script publicly, though these attacks are bound to be replicated independently. Since the attack is very recent, patches will begin rolling out soon, which makes it important to stay up to date and check for firmware patches for your devices as soon as they're released.