
WhisperPair exposes Google Fast Pair to Bluetooth hijacking in headphones
Belgian researchers warn of WhisperPair, a set of security flaws in Google’s Fast Pair protocol that can let a nearby attacker secretly pair with certain Bluetooth headphones and speakers, potentially eavesdropping on mics and tracking users via Google’s Find Hub. In tests, 17 of more than two dozen devices were hackable, including Sony WH-1000XM6/XM5/XM4 and Pixel Buds Pro 2. Google and OEMs have released fixes, but a bypass exists; with Fast Pair not being disableable, firmware updates from manufacturers are the main protection.

