IoT, Vulnerability Management, Patch/Configuration Management

WhisperPair vulnerabilities expose Bluetooth audio devices to hijacking

Bluetooth logo on phone screen

As detailed in ZDNET, a new set of vulnerabilities dubbed WhisperPair has been disclosed, affecting the common protocol used for pairing Bluetooth audio devices. These flaws could allow attackers to gain unauthorized control over headphones and earbuds.

WhisperPair vulnerabilities stem from improper implementation of Google's Fast Pair protocol, which enables quick device connections. Attackers can exploit this by initiating unauthorized pairing, potentially hijacking audio devices. This allows them to tamper with controls and, more concerningly, eavesdrop on conversations through the device's microphone. The attacks have been demonstrated to work wirelessly up to a range of 14 meters. Furthermore, if a vulnerable device is not yet registered to Google's Find Hub network, attackers could register it to their own account, enabling them to track the device and its owner. Several major vendors, including Google, Sony, and JBL, have devices listed as vulnerable, impacting both Android and iPhone users.

Many vendors have begun issuing patches, and the ongoing risk underscores the need for users to promptly update their audio accessories' firmware. The inability to disable Fast Pair on many devices means that firmware updates are the sole mitigation.

Source: ZD NET

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds