The WhisperPair vulnerability threatens hundreds of millions of headphones.
A vulnerability known as WhisperPair allows hijacking of Bluetooth headsets using Google Fast Pair, paving the way for eavesdropping and location tracking.
Báo Khoa học và Đời sống•21/01/2026
A research team from the University of Leuven has published a series of serious security vulnerabilities in Bluetooth headphones that support Google Fast Pair. The WhisperPair attack technique allows attackers to take control of the headset without any user intervention.
The vulnerability stems from Fast Pair's failure to check the pairing status, allowing unauthorized devices to establish a connection even when the headset is in use.
After gaining control, the attacker can illegally play audio, activating the microphone to eavesdrop on the surrounding environment.
Even more dangerously, they can assign their Google account as the owner and track the headphones' location via the Find Hub network. Google has rated this as a high-severity vulnerability with the code CVE-2025-36911. The solution cannot be achieved simply by updating the phone; it depends on the firmware released by the headphone manufacturer.
Numerous major brands such as Sony, JBL, Jabra, Xiaomi, and Google have been affected, causing the risk to spread to hundreds of millions of users worldwide. Readers are invited to watch the following video : Online kidnapping scam scenario that "manipulates the psychology" of many victims | VTV24
Comment (0)