Your Bluetooth Audio Devices Could Be at Risk of Hijacking, Researchers Say


Researchers working at KU Leuven University in Belgium are warning Bluetooth audio product users that their devices may be at risk due to vulnerabilities in Google’s Fast Pair technology, a feature that makes it quicker and easier to connect Bluetooth devices.

Google says it has addressed issues that could allow hackers to hijack audio devices and track their location. But the researchers say the vulnerabilities, which it collectively refers to as WhisperPair, still affect products from device makers including Sony, Harman and Google itself. In their tests, the researchers found these products could be hacked from as far as about 46 feet away.

A Google representative told CNET that it has updated the software for some of its own audio products, including its Pixel Buds Pro, and that some of the vulnerabilities stemmed from other companies not properly following Fast Pair specifications. Google said it had informed companies about this in September.


Don’t miss any of our unbiased tech content and lab-based reviews. Add CNET as a preferred Google source.


“We appreciate collaborating with security researchers through our Vulnerability Rewards Program, which helps keep our users safe. We worked with these researchers to fix these vulnerabilities, and we have not seen evidence of any exploitation outside of this report’s lab setting,” Google said in a statement provided to CNET. “As a best security practice, we recommend users check their headphones for the latest firmware updates. We are constantly evaluating and enhancing Fast Pair and Find Hub security.”

In response to specific concerns about device tracking, Google added, “We rolled out a fix on our end to prevent Find Hub network provisioning in this scenario, which completely addresses the potential location tracking issue across all devices.”

The WhisperPair research group said it’s working on an academic paper that will detail its findings. On its website, the researcher group said, “Our findings show how a small usability ‘add-on’ can introduce large-scale security and privacy risks for hundreds of millions of users.”

The research group released a YouTube video discussing problems with Fast Pair, a Google technology that was introduced in 2017 to connect Bluetooth devices with one tap across Android and Chrome OS.

The group said that it worked with Google after reporting its findings and was awarded a $15,000 bounty. The researchers said they agreed to a 150-day disclosure window in which Google would release security patches. However, the website points out that users of Bluetooth devices like earbuds may not be aware of security updates that could protect them.

The website includes a page where users can look up which audio products are vulnerable, with details on how to get them updated. Google doesn’t have detailed information about these vulnerabilities on its Fast Pair Known Issues page.





Source link

  • Related Posts

    Snowflake, Databricks challenger ClickHouse hits $15B valuation

    Database provider ClickHouse secured $400 million at a $15 billion valuation, Bloomberg reported, representing about a 2.5x increase from its $6.35 billion valuation last May. The round was led by…

    EFF to California Appeals Court: First Amendment Protects Journalist from Tech Executive’s Meritless Lawsuit

    EFF asked a California appeals court to uphold a lower court’s decision to strike a tech CEO’s lawsuit against a journalist that sought to silence reporting the CEO, Maury Blackman,…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Video Astronauts return to Earth after first-ever medical evacuation from ISS

    Video Astronauts return to Earth after first-ever medical evacuation from ISS

    Why the ‘Are You Dead?’ app is going viral in China

    Why the ‘Are You Dead?’ app is going viral in China

    Bath 63-10 Edinburgh: Hosts seal home last-16 Investec Champions Cup game

    Bath 63-10 Edinburgh: Hosts seal home last-16 Investec Champions Cup game

    The Best Items From the Shopbop Sale January 2026

    The Best Items From the Shopbop Sale January 2026

    Christina Lake Cannabis Announces Sale of Bare Land

    Snowflake, Databricks challenger ClickHouse hits $15B valuation

    Snowflake, Databricks challenger ClickHouse hits $15B valuation