Cyber Security News

WPair – Scanner Tool to Detect WhisperPair Flaw in Google’s Fast Pair Protocol

WPair is an Android application designed to identify and demonstrate the CVE-2025-36911 vulnerability affecting millions of Bluetooth audio devices worldwide.

The tool addresses a critical authentication bypass flaw discovered by KU Leuven researchers in Google’s Fast Pair protocol, commonly referred to as WhisperPair.​

CVE-2025-36911 represents a systemic failure in Fast Pair implementations across multiple manufacturers and chipsets. The vulnerability stems from improper enforcement of pairing mode verification.

WPair Scanner for WhisperPair Flaw (source: zalexdev GitHub)

According to the WhisperPair research, many devices fail to disregard pairing requests from unauthorized sources when not explicitly in pairing mode.

Allowing attackers to forcibly establish connections within seconds at ranges up to 14 meters. The attack requires no user interaction or physical device access, making it particularly dangerous for consumer audio equipment.​

WPair Functionality

The application provides three core scanning and testing modes. The BLE Scanner discovers nearby Fast Pair devices by identifying devices that broadcast the 0xFE2C service UUID.

The Vulnerability Tester performs non-invasive checks to determine patch status without establishing connections.

For authorized security research, the Exploit feature demonstrates the complete attack chain, including key-based pairing bypass, BR/EDR address extraction, and Bluetooth Classic bonding.​

FeatureDescription
BLE ScannerDetects Fast Pair devices in real time
Vulnerability TesterChecks CVE-2025-36911 patch status safely
Exploit DemoProof-of-concept for authorized testing
HFP Audio AccessShows microphone access after exploit
Live ListeningStreams audio to phone instantly
Audio RecordingSaves captured audio for analysis
Device Status DetectionFlags devices in pairing mode
Key-Based BypassDemonstrates Fast Pair auth bypass
BR/EDR ExtractionRetrieves Bluetooth Classic addresses
Classic BondingCreates persistent audio connections
Account Key PersistenceDemonstrates long-term device tracking

Post-exploitation capabilities include accessing the Hands-Free Profile for microphone functionality.

Users can enable live audio streaming directly to their phone speaker or save captured audio as M4A files for forensic analysis.​

The vulnerability allows attackers to hijack devices without authorization, enabling them to control audio playback, record conversations, and potentially establish persistent tracking through Google’s Find Hub Network.

If a device has never connected to an Android device, attackers can add it to their own account for location tracking, exploiting the mechanism that designates the first Account Key writer as the device owner.​

WPair Work flow (source: zalexdev GitHub)

Affected manufacturers include JBL, Harman Kardon, Sony, Marshall, and numerous others, impacting an estimated hundreds of millions of users globally.

Technical Requirements and Installation Options

CategoryDetails
Minimum Android VersionAndroid 8.0 (API 26) or higher
Bluetooth SupportBluetooth Low Energy (BLE) required
PermissionsLocation permissions (or Nearby Devices on Android 13+)
Installation – APKDownload pre-compiled APK from Releases
Installation – Source BuildBuild from source using Gradle

Google classified this issue as critical and awarded researchers the maximum $15,000 bounty. The 150-day disclosure window ended in January 2026, and manufacturers are now releasing patches.

WPair explicitly excludes Find Hub Network provisioning functionality to maintain ethical boundaries around stalkerware implementation.​

WPair requires Android 8.0 or higher with Bluetooth LE support and appropriate location permissions. The application is available both as a precompiled APK and as a compiled source via Gradle.

According to the advisory, security researchers should verify they possess explicit written authorization before testing devices they do not own.

The tool represents a significant advancement in vulnerability assessment for the IoT audio ecosystem, enabling manufacturers and security teams to identify affected devices requiring immediate firmware updates.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…

5 hours ago

AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge

Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…

6 hours ago

SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams

SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…

7 hours ago

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…

7 hours ago

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…

7 hours ago

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

7 hours ago