Fork me on Github
Fork me on Github

Joe Dog Software

Proudly serving the Internets since 1999

A Flaw In Fast Pair Bluetooth Protocol Allows Hackers To Stalk You

by Jeff Fulmer | Published: 2026-01-15 19:21:39

Do you have a stalker ex who wants to make your life miserable? Then I have bad news. A critical flaw in Google's Fast Pair protocol can allow nefarious actors to track your movements and eavesdrop on your conversations. Security researchers at Belgium’s KU Leuven University have the details

The team found seventeen audio devices sold by ten different companies that are vulnerable to an attack. Hundreds of millions of people are vulnerable, even those who've never owned a Google device. In their tests, the team connected to vulnerable devices within Bluetooth range, then controlled audio, eavesdropped on a conversation, played music, and tracked the victim using Find Hub.

The researchers discovered the flaw in August and notified Google, which alerted all manufacturers. Fixes are available from the OEM. But here's the thing: These are devices. The patch must be installed in the firmware. That requires downloading an installer app to a phone or laptop, then using the app to update the device's firmware. Given the total number of digital clocks blinking "12:00," this flaw will be with us for years to come. 

The following devices are listed as vulnerable on the Whisper Pair site:

SonyWH-1000XM6 Patch installer
SonyWH-1000XM5Patch installer
SonyWH-CH720NPatch installer
SonyWF-1000XM5Patch installer
SonyWH-1000XM4Patch installer
GooglePixel Buds Pro 2Update instructions
OnePlusNord Buds 3 ProUpdate instructions
NOTHINGNothing Ear (a)Patch installer
HarmanJBL TUNE BEAMPatch installer
XiaomiRedmi Buds 5 ProUpdate instructions
MarshallMOTIF II A.N.C.Update instructions
Ankersoundcore Liberty 4 NCWindows | Phone app
JabraElite 8 ActivePatch installer