Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent

WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent

Posted on January 20, 2026January 20, 2026 By CWS

A essential vulnerability in Google’s Quick Pair protocol that enables attackers to hijack Bluetooth audio equipment and observe customers with out their data or consent.​

Safety researchers from KU Leuven have uncovered a vulnerability, tracked as CVE-2025-36911 and dubbed WhisperPair, that impacts tons of of hundreds of thousands of wi-fi earbuds, headphones, and audio system from main producers.

Together with Sony, Anker, Google, Jabra, JBL, Logitech, Marshall, Nothing, OnePlus, Soundcore, and Xiaomi.

Google labeled the difficulty as essential and awarded the researchers the utmost attainable bounty of $15,000.​ The flaw stems from the improper implementation of the Quick Pair protocol.

Essential Flaw in Quick Pair Implementation

In response to the Quick Pair specification, Bluetooth equipment ought to ignore pairing requests when not in pairing mode.

Nonetheless, many flagship gadgets fail to implement this essential safety test, permitting unauthorized gadgets to provoke the pairing course of with out person interplay.​

Attackers can exploit WhisperPair utilizing any customary Bluetooth-capable system reminiscent of a laptop computer, smartphone, or Raspberry Pi.

Attacker’s dashboard with location from the Discover Hub community (supply: whisperpair )

The assault succeeds inside a median of 10 seconds at ranges as much as 14 meters with out requiring bodily entry to the weak system.

As soon as paired, attackers achieve full management over the audio accent, enabling them to play audio at excessive volumes or report conversations by means of the built-in microphone.​

Moreover, if an adjunct has by no means been paired with an Android system, attackers can add it to their very own Google account and observe the sufferer’s location utilizing Google’s Discover Hub community.

The monitoring notification that seems reveals the sufferer’s personal system, which can lead customers to dismiss the warning as a system bug, permitting extended surveillance.​

Undesirable monitoring notification displaying the sufferer’s personal system (supply: whisperpair )

Cross-Platform Vulnerability

The vulnerability impacts customers throughout all platforms as a result of the flaw exists within the equipment themselves, not in smartphones.

iPhone customers with weak Bluetooth gadgets face the identical dangers as Android customers. Since Quick Pair performance can’t be disabled on equipment, even customers outdoors the Android ecosystem stay weak.​

The WhisperPair researchers reported their findings to Google in August 2025, agreeing to a 150-day disclosure window for producers to launch safety patches.

The one efficient mitigation is putting in firmware updates from system producers.

Whereas many producers have launched patches, software program updates might not but be accessible for all weak gadgets.

Customers ought to seek the advice of their accent’s guide for firmware replace directions and confirm patch availability immediately with producers.​

The WhisperPair vulnerability represents a systemic failure, as weak gadgets handed each producer high quality assurance and Google’s certification course of earlier than reaching the market at scale.​

Comply with us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:Attack, Consent, Earbuds, Hijacking, Laptops, User, WhisperPair

Post navigation

Previous Post: Pulsar RAT Using Memory-Only Execution & HVNC to Gain Invisible Remote Access
Next Post: Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion

Related Posts

Hackers Compromise Active Directory to Steal NTDS.dit that Leads to Full Domain Compromise Hackers Compromise Active Directory to Steal NTDS.dit that Leads to Full Domain Compromise Cyber Security News
76 Zero-day Vulnerabilities Uncovered by Hackers on Pwn2Own Automotive 2026 76 Zero-day Vulnerabilities Uncovered by Hackers on Pwn2Own Automotive 2026 Cyber Security News
Record-breaking 11.5 Tbps UDP Flood DDoS Attack Originated from Google Cloud Platform Record-breaking 11.5 Tbps UDP Flood DDoS Attack Originated from Google Cloud Platform Cyber Security News
Scans From Hacked Cisco Small Business Routers, Linksys and Araknis are at the Raise Scans From Hacked Cisco Small Business Routers, Linksys and Araknis are at the Raise Cyber Security News
Muddled Libra Actors Attacking Organizations Call Centers for Initial Infiltration Muddled Libra Actors Attacking Organizations Call Centers for Initial Infiltration Cyber Security News
New Phishing Attack Abusing Blob URLs to Bypass SEGs and Evade Analysis New Phishing Attack Abusing Blob URLs to Bypass SEGs and Evade Analysis Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News