Hijacking Bluetooth Accessories Using Google Fast Pair: WhisperPair CVE-2025-36911 Reference Implementation & Vulnerability Verification Toolkit

Hijacking Bluetooth Accessories Using Google Fast Pair: WhisperPair CVE-2025-36911 Reference Implementation & Vulnerability Verification Toolkit

Published 6 Jul 2026Updated 6 Jul 202612 sources
CVSS 0.0 PoC CANDIDATE

What happened

A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.

Affected versions

Unknown product: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
PoC-in-GitHub · SpectrixDev/DIY_WhisperPairHijacking Bluetooth Accessories Using Google Fast Pair: WhisperPair CVE-2025-36911 Reference Implementation & Vulnerability Verification Toolkit★ 105SpectrixDev2026-01-17CandidatePoC-in-GitHub · Cedric-Martz/CVE-2025-36911_scanThis script can be used to check if a Bluetooth device is vulnerable to CVE-2025-36911.★ 4Cedric-Martz2026-01-17CandidatePoC-in-GitHub · zalexdev/wpair-appWPair is a defensive security research tool that demonstrates the CVE-2025-36911 (eg WhisperPair) vulnerability in Google's Fast Pair protocol. This vulnerability affects millions of Bluetooth audio devices worldwide, allowing unauthorized pairing and potential microphone access without user consent.★ 840zalexdev2026-01-17CandidatePoC-in-GitHub · SteamPunk424/CVE-2025-36911-Wisper_Pair_Target_FinderThis is not an exploit for CVE-2025-36911!!! This is a detector for finding potentially vulnerable devices! Only use on your own devices! I am not responsible for damages!★ 2SteamPunk4242026-01-17CandidatePoC-in-GitHub · PivotChip/FrostedFastPairWhisperPair (CVE-2025-36911) POC for ESP32 device★ 14PivotChip2026-01-20CandidatePoC-in-GitHub · ap425q/whisper-pairA Vulnerablity Scanner for Whisper Pair (CVE-2025-36911)★ 2ap425q2026-01-21CandidatePoC-in-GitHub · aalex954/whisperpair-poc-toolA security research tool that identifies and demonstrates the CVE-2025-36911: Fast Pair Pairing Mode Bypass vulnerability★ 8aalex9542026-01-25CandidatePoC-in-GitHub · PentHertz/CVE-2025-36911-exploitExploit of the CVE-2025-36911 vulnerability in Python for testing our own equipment★ 27PentHertz2026-01-27CandidatePoC-in-GitHub · Athexblackhat/BLUE-SPYBLUE-SPY (Bluetooth Low Energy Universal Exploit - Security Penetration Testing) is a professional security assessment tool for analyzing CVE-2025-36911 vulnerabilities in Google's Fast Pair protocol implementation.★ 7Athexblackhat2026-02-19CandidatePoC-in-GitHub · KULeuven-COSIC/WhisperPairThe official reference implementation & vulnerability verification of our attack WhisperPair (CVE-2025-36911) which affects Google's Fast Pair protocol.★ 89KULeuven-COSIC2026-03-30CandidatePoC-in-GitHub · Ymsniper/Whisper_BullyThree-stage Bluetooth BDADDR extraction, DoS & hijack on Fast Pair devices; unpatched primitives outside CVE-2025-36911 scope (no Ubertooth needed)★ 37Ymsniper2026-07-07Candidate