Close Menu
Canadian ReviewsCanadian Reviews
  • What’s On
  • Reviews
  • Digital World
  • Lifestyle
  • Travel
  • Trending
  • Web Stories
Trending Now
How I Pack For a 7-Day Disney World Trip With A Single Carry-On

How I Pack For a 7-Day Disney World Trip With A Single Carry-On

How Colin Stetson Crafted the Bone-Chilling Score for ‘Something Very Bad Is Going to Happen’

How Colin Stetson Crafted the Bone-Chilling Score for ‘Something Very Bad Is Going to Happen’

Bissell steam cleaners recalled due to burn risk

Bissell steam cleaners recalled due to burn risk

The 3 best racing games to play before Forza Horizon 6

The 3 best racing games to play before Forza Horizon 6

Ricoh GR IV Monochrome review: Why I love this camera that can’t shoot color

Ricoh GR IV Monochrome review: Why I love this camera that can’t shoot color

1960 Elvis Presley Hit Turned a Future '70s Soul Superstar’s Life Around—You Won’t Believe How

Kidney donor may be ineligible for refugee claim

Kidney donor may be ineligible for refugee claim

Facebook X (Twitter) Instagram
  • Privacy
  • Terms
  • Advertise
  • Contact us
Facebook X (Twitter) Instagram Pinterest Vimeo
Canadian ReviewsCanadian Reviews
  • What’s On
  • Reviews
  • Digital World
  • Lifestyle
  • Travel
  • Trending
  • Web Stories
Newsletter
Canadian ReviewsCanadian Reviews
You are at:Home » Sony, Anker, and other headphones have a serious Google Fast Pair security vulnerability
Sony, Anker, and other headphones have a serious Google Fast Pair security vulnerability
Digital World

Sony, Anker, and other headphones have a serious Google Fast Pair security vulnerability

16 January 20263 Mins Read

Several Bluetooth audio devices from companies like Sony, Anker, and Nothing are susceptible to a new flaw that can allow attackers to listen in on conversations or track devices that use Google’s Find Hub network, as reported by Wired.

Researchers from KU Leuven University’s Computer Security and Industrial Cryptography group in Belgium discovered several vulnerabilities in Google’s Fast Pair protocol that can allow a hacker within Bluetooth range to secretly pair with some headphones, earbuds, and speakers. The attacks, which the researchers have collectively dubbed WhisperPair, can even be used on iPhone users with affected Bluetooth devices despite Fast Pair being a Google-specific feature.

Fast Pair streamlines Bluetooth pairing and lets wireless audio accessories connect to Android or Chrome OS devices by simply tapping them together. But the researchers found that many devices don’t implement Fast Pair correctly, including a Google specification that says Fast Pair devices shouldn’t be able to connect to a new device while already paired to another.

The researchers tested their WhisperPair attacks on over two dozen Bluetooth devices and were successful in hacking 17 of them. They were able to play their own audio through the compromised headphones and speakers at any volume, intercept phone calls, and even eavesdrop on conversations using the devices’ microphones.

A more serious issue was found to affect five Sony products and Google’s Pixel Buds Pro 2. If the devices weren’t previously connected to an Android device and linked to a Google account (which isn’t required when using them with iPhones), WhisperPair could be used to pair and link them to a hacker’s Google account that would be recognized as the device’s owner. That would allow a hacker to use Google’s Find Hub network to track the user’s location and movements through their headphones, assuming smartphone notifications warning that a device was tracking them were dismissed as errors.

The researchers reported their findings to Google in August 2025. The company then recommended fixes to its “accessory OEM partners” in September and updated its certification requirements to mitigate similar issues going forward. “We worked with these researchers to fix these vulnerabilities, and we have not seen evidence of any exploitation outside of this report’s lab setting,” Google spokesperson Ed Fernandez says in a written statement to The Verge.

The recommended fixes resolve all the Fast Pair issues once a software update has been installed, but Google implemented an additional Find Hub network update to prevent WhisperPair from being used to track certain Bluetooth devices that haven’t been patched. The researchers told Wired it only took them a few hours to bypass that patch and continue their tracking. According to Fernandez, the researchers used “old/not updated accessory OEM firmware in order to execute their workaround,” and Google is “looking into the bypass for this additional fix,” which was only submitted earlier this week.

The Fast Pair feature can’t be disabled, so the only way to protect against WhisperPair attacks is for users to install firmware updates released by manufacturers that resolve the vulnerabilities. The Verge reached out to all the manufacturers with affected hardware to confirm the progress of fixes. Spenser Blank, the head of marketing & communications for OnePlus North America, told The Verge in a written statement that the company “takes all security reports seriously” and that it’s “currently investigating this matter and will take appropriate action to protect our users’ security and privacy.”

We will update this story as other companies respond.

Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email

Related Articles

Ricoh GR IV Monochrome review: Why I love this camera that can’t shoot color

Ricoh GR IV Monochrome review: Why I love this camera that can’t shoot color

Digital World 12 April 2026
Google’s latest Nest Doorbells just hit their lowest prices of the year

Google’s latest Nest Doorbells just hit their lowest prices of the year

Digital World 11 April 2026
Google says Polymarket bets showing up in News was an ‘error’

Google says Polymarket bets showing up in News was an ‘error’

Digital World 11 April 2026
You don’t have to spend more than  on a great USB-C dock for your Switch 2

You don’t have to spend more than $50 on a great USB-C dock for your Switch 2

Digital World 11 April 2026
The Audacity is a new show making fun of tech brosThe new show making fun of tech bros

The Audacity is a new show making fun of tech brosThe new show making fun of tech bros

Digital World 11 April 2026
Is the ‘Holy Grail of batteries’ finally ready to bless us with its presence?

Is the ‘Holy Grail of batteries’ finally ready to bless us with its presence?

Digital World 11 April 2026
Top Articles
9 Longest-Lasting Nail Polishes, Tested by Top Manicurists

9 Longest-Lasting Nail Polishes, Tested by Top Manicurists

25 January 2026179 Views
Forbes ranked Canada’s top employers for 2026 and over 30 Quebec companies made the cut

Forbes ranked Canada’s top employers for 2026 and over 30 Quebec companies made the cut

22 January 202699 Views
Canada’s best employers for 2026 were revealed and these are the top companies to work for

Canada’s best employers for 2026 were revealed and these are the top companies to work for

21 January 202698 Views
The Mother May I Story – Chickpea Edition

The Mother May I Story – Chickpea Edition

18 May 202497 Views
Demo
Don't Miss
Lifestyle 12 April 2026

1960 Elvis Presley Hit Turned a Future '70s Soul Superstar’s Life Around—You Won’t Believe How

In 1960, a chart-topping Elvis Presley song did more than dominate the airwaves—it unexpectedly turned…

Kidney donor may be ineligible for refugee claim

Kidney donor may be ineligible for refugee claim

Sarah Silverman, Andrew Rannells, Keyla Monterroso & 6 More Round Out the Cast of ‘Nobody Wants This’ Season 3

Sarah Silverman, Andrew Rannells, Keyla Monterroso & 6 More Round Out the Cast of ‘Nobody Wants This’ Season 3

1963 Classic Rock Hit Ranked 'Greatest Beach Song' of All Time

About Us
About Us

Canadian Reviews is your one-stop website for the latest Canadian trends and things to do, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
How I Pack For a 7-Day Disney World Trip With A Single Carry-On

How I Pack For a 7-Day Disney World Trip With A Single Carry-On

How Colin Stetson Crafted the Bone-Chilling Score for ‘Something Very Bad Is Going to Happen’

How Colin Stetson Crafted the Bone-Chilling Score for ‘Something Very Bad Is Going to Happen’

Bissell steam cleaners recalled due to burn risk

Bissell steam cleaners recalled due to burn risk

Most Popular
Why You Should Consider Investing with IC Markets

Why You Should Consider Investing with IC Markets

28 April 202429 Views
OANDA Review – Low costs and no deposit requirements

OANDA Review – Low costs and no deposit requirements

28 April 2024362 Views
LearnToTrade: A Comprehensive Look at the Controversial Trading School

LearnToTrade: A Comprehensive Look at the Controversial Trading School

28 April 202476 Views
© 2026 ThemeSphere. Designed by ThemeSphere.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us

Type above and press Enter to search. Press Esc to cancel.