WhisperPair Flaw Lets Hackers Hijack Earbuds
Security researchers have uncovered a critical Bluetooth vulnerability known as the WhisperPair flaw, which exposes millions of wireless earbuds, headphones, and speakers to remote hijacking and tracking. The issue stems from a misimplementation of Google’s Fast Pair protocol, affecting devices from major brands including Sony, Anker, JBL, and Xiaomi.
Researchers from KU Leuven found that many accessories accept unauthorized pairing requests even outside pairing mode. Attackers can exploit this using standard Bluetooth-enabled devices, gaining control in under 10 seconds from up to 14 meters away.
Once connected, attackers can play loud audio, record conversations, or—if the device has never been paired—link it to their own Google account to track the user’s location. Notifications often mislead victims by showing their own device, increasing the risk of ongoing surveillance.
The WhisperPair flaw affects users across platforms, including iPhone. Only firmware updates from manufacturers can fix the issue.
Read the full story at
WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent – Millions Affected
