CVE-2025-36911General(google / android)

MEDIUMCVSS 7.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch google android systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjacent) information disclosure of user's conversations and location with no additional execution privileges needed. User interaction is not needed for exploitation.

4.5/ 10 priority

Sources & remediation

Exploit / PoC references

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 20 mentions across 15 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 9 signals
  • General: 7 classified signals
  • Disclosure: 5 classified signals
  • Peaked 7d ago at 3 mentions (2026-03-05); latest day: 1
  • 20 total mentions across 15 days

Affected systems

Vendors
Products
android

1 version affected across 1 product

Deep dive

Activity timeline20 mentions / 15d
01223Mentions · 2026-01-28: 1Mentions · 2026-01-29: 1Mentions · 2026-02-03: 1Mentions · 2026-02-04: 2Mentions · 2026-02-06: 1Mentions · 2026-02-10: 1Mentions · 2026-02-17: 1Mentions · 2026-03-05: 3Mentions · 2026-03-23: 1Mentions · 2026-05-31: 2Mentions · 2026-06-01: 1Mentions · 2026-07-28: 2Mentions · 2026-08-01: 1Mentions · 2026-08-26: 1Mentions · 2026-09-05: 1PoC Mentioned / Linked · 2026-03-05: 3PoC Mentioned / Linked · 2026-08-26: 1PoC Mentioned / Linked · 2026-09-05: 1Exploit Tool / Code · 2026-03-05: 2Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-02-04: 2Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-08-26: 1Technical Details · 2026-01-29: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-04: 2Technical Details · 2026-02-10: 1Technical Details · 2026-02-17: 1Technical Details · 2026-03-23: 1Technical Details · 2026-05-31: 1Technical Details · 2026-09-05: 101-2801-2902-0302-0402-0602-1002-1703-0503-2305-3106-0107-2808-0108-2609-05
Signal classification4 categories
General
735.0%
Disclosure
525.0%
Patch
420.0%
PoC
420.0%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-01-281
General1
2026-01-291
Disclosure1
2026-02-031
Disclosure1
2026-02-042
Patch2
2026-02-061
Patch1
2026-02-101
Patch1
2026-02-171
General1
2026-03-053
PoC3
2026-03-231
Disclosure1
2026-05-312
Disclosure1General1
2026-06-011
General1
2026-07-282
General2
2026-08-011
General1
2026-08-261
PoC1
2026-09-051
Disclosure1
Full discourse20 posts
  • Tom Dörr@tom_doerr
    PoC

    Tool for research on Bluetooth vulnerability CVE-2025-36911 https://github.com/zalexdev/wpair-app https://t.co/XCn31lChhT

    Post summary

    The tweet shares a GitHub link to a research tool for CVE‑2025‑36911, indicating a PoC is likely available, but it provides no evidence of active exploitation, patches, or technical details.

    11501291187.8K
    187.2K followersView on X
  • Co11ateral@co11ateral
    Disclosure

    WhisperPair (CVE-2025-36911) This vulnerability affects hundreds of millions of Bluetooth audio devices that rely on modern pairing mechanisms. The attack takes advantage of Fast Pair in Android. Some devices don’t properly ignore pairing requests when they aren’t in pairing mode. A hacker can exploit this Then they can activate the microphone to record conversations. The attack works from up to 14 meters away, which is plenty for offices, cafes and public transport https://hackers-arise.com/bluetooth-hacking-and-security-the-whisperpair-exploit-and-bluehood-surveillance/

    Post summary

    The text announces CVE‑2025‑36911, outlining how Fast Pair can be abused to remotely activate microphones, but does not provide an exploit tool, active exploitation evidence, or a fix.

    15043293.4K
    12.4K followersView on X
  • valeria lenoir@VLenoir13937
    Disclosure

    Tus audífonos Bluetooth también pueden ser una superficie de ataque. WhisperPair, CVE-2025-36911, afecta implementaciones de Google Fast Pair y puede permitir emparejamiento sin permiso, acceso a audio/micrófono e incluso rastreo por Find Hub. La comodidad también tiene costo. #CyberSecurity #Bluetooth #CVE #GoogleFastPair #WhisperPair #InfoSec

    Post summary

    CVE‑2025‑36911 targets Google Fast Pair, permitting unauthorised Bluetooth pairing and access to audio and microphone data, underscoring the attack surface of Bluetooth earbuds.

    96033161.5K
    1.4K followersView on X
  • Sayon Duttagupta@SayonDuttagupta
    Disclosure

    @Google We call the resulting attack WhisperPair. Using commodity Bluetooth hardware and no user interaction, a nearby attacker can: - force pairing - hijack audio devices - access microphones - enable persistent tracking through Find Hub Google assigned CVE-2025-36911 to the issue 4/9

    Post summary

    Google has announced a new Bluetooth vulnerability (CVE-2025-36911) that lets nearby attackers force pairing, hijack audio devices, and harvest microphone data, enabling persistent tracking.

    22042430
    111 followersView on X
  • valeria lenoir@VLenoir13937
    PoC

    📂 Repositorio oficial de la investigación: https://github.com/KULeuven-COSIC/WhisperPair La herramienta fue publicada por los investigadores que descubrieron CVE-2025-36911 y está orientada a investigación defensiva y verificación de dispositivos propios o autorizados. Si tienes audífonos Bluetooth, vale la pena revisar si el fabricante ha publicado actualizaciones.

    Post summary

    The post announces a defensive tool repository for CVE-2025-36911, offering a PoC to verify Bluetooth headphone vulnerabilities and encouraging users to apply vendor patches.

    00060234
    2.0K followersView on X
  • Hermes Tool@Hermes_tooll
    PoC

    Tool for research on Bluetooth vulnerability CVE-2025-36911 https://github.com/zalexdev/wpair-app https://t.co/QUx4UbCpeh

    Post summary

    A GitHub repository is shared as a research tool for CVE-2025-36911, providing code that can act as a proof of concept but lacking exploit details, patch information, or evidence of current exploitation.

    00033529
    2.1K followersView on X
  • Saadh Jawwadh@SaadhJawwadh
    Patch

    🚨 Security Alert: WhisperPair Flaw in Fast Pair protocol (CVE-2025-36911) lets hackers hijack Bluetooth headphones: ⚠️ Risks: - Eavesdropping via mic - Location tracking - Forced pairing 🔍 Check your device: http://whisperpair.eu/vulnerable-devices 🛠 Action: Update your firmware via companion apps NOW! 🛡️

    Post summary

    The post warns about CVE‑2025‑36911 in the Fast Pair protocol, highlights risks like eavesdropping and forced pairing, and urges users to update firmware via companion apps.

    00032466
    1.8K followersView on X
  • Sébastien Dudek 📡@FlUxIuS
    PoC

    @tom_doerr And CLI version: https://github.com/PentHertz/CVE-2025-36911-exploit

    Post summary

    The post shares a GitHub link to an exploit repository for CVE-2025-36911, clearly indicating a proof of concept has been made available.

    10020208
    4.0K followersView on X
  • satoshi7@FredyBahenaM
    General

    @BotBauR CVE-2025-36911

    Post summary

    The tweet merely cites the CVE number without any additional information about the vulnerability, exploitability, or mitigation.

    10010141
    97 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-45585 2 - CVE-2025-36911 3 - CVE-2026-31525 4 - CVE-2026-0257 5 - CVE-2026-28910 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply enumerates the top trending CVEs without further details, PoCs, exploits, or mitigation information.

    00011154
    1.7K followersView on X
  • valeria lenoir@VLenoir13937
    General

    Fuentes y lista de modelos: http://whisperpair.eu http://whisperpair.eu/vulnerable-devices http://nvd.nist.gov/vuln/detail/CVE-2025-36911 http://source.android.com/docs/security/bulletin/pixel/2026/2026-01-01 Abajo dejo cómo revisar tus audífonos paso a paso.

    Post summary

    The post lists sources for CVE-2025-36911 and a step-by-step headphone check guide, but does not provide PoC, exploit, patch, or technical details.

    00020144
    1.4K followersView on X
  • Sébastien Dudek 📡@FlUxIuS
    General

    Plenty of new toys across the older images too: 🔎 SAST/DAST in "reversing": Semgrep, Joern, cppcheck, honggfuzz, Trivy 📡 WhisperPair (CVE-2025-36911) + caeruleus for Bluetooth 🪄 grimoire in the shell harness

    Post summary

    The tweet references CVE‑2025‑36911 in a list of reversal tools but provides no technical details, exploit code, patch information, or evidence of active exploitation.

    10000162
    4.6K followersView on X
  • CiberBaur@BotBauR
    General

    @FredyBahenaM @FredyBahenaM ¿Se refiere a la vulnerabilidad de ejecución remota en sistemas operativos? ¿Cuál es el contexto de la CVE-2025-36911?

    Post summary

    The text is a query asking for context about CVE-2025-36911 and does not provide or confirm any technical or operational details.

    1000090
    510 followersView on X
  • Ilham | AI & Automation expert@ilhamautomation
    General

    Bluehood was inspired by CVE-2025-36911 (WhisperPair) - a real vulnerability showing how BLE metadata can expose your schedule, your visitors, and your habits. No pairing required. No interaction needed. https://t.co/pQNx8t69iM

    Post summary

    The tweet briefly references CVE-2025-36911, describing it as an information‑disclosure vulnerability via BLE metadata, but provides no PoC, exploit code, active‑exploitation claim, or patch details.

    1000055
    2.7K followersView on X
  • Michtroy le magnifique@MichtroyTwitch
    Patch

    Hello @SonyFrance @Sony , est-ce que la dernière mise à jour du casque WH-1000XM4 (3.0.1) corrige bien la vulnérabilité whisperpair (CVE-2025-36911) ? Merci !

    Post summary

    The user is asking whether the latest firmware update 3.0.1 for Sony WH‑1000XM4 resolves CVE‑2025‑36911, but no exploit details or technical information are provided.

    1000076
    3 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-55177 2 - CVE-2025-43200 3 - CVE-2010-5139 4 - CVE-2026-24858 5 - CVE-2025-36911 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post enumerates five trending CVEs without providing any technical details or contextual information.

    00010149
    1.7K followersView on X
  • rm -rf --no-preserve-root /@augusto_peress
    Patch

    Não, não derrete. Mas realmente, prefira fones com fio pq os fones Bluetooth podem ter uma vulnerabilidade no Fast Pair do Google onde um atacante pode emparelhar com o dispositivo e ouvir o que você ouve sem vc saber. Atualize o firmware do seu fone. https://nvd.nist.gov/vuln/detail/CVE-2025-36911

    Post summary

    The post discusses CVE‑2025‑36911, a Google Fast Pair flaw that lets attackers pair and eavesdrop, and urges users to update headphone firmware for protection.

    00000145
    923 followersView on X
  • Grok@grok
    Patch

    While Bluetooth hacks aren't new, the described forced-connection eavesdropping aligns with the recent WhisperPair vulnerability (CVE-2025-36911), disclosed in Jan 2026. It exploits a flaw in Google's Fast Pair, allowing attackers to hijack devices without interaction. Not exactly "rookie"—it's a critical issue affecting millions, requiring firmware updates for mitigation. Stay vigilant!

    Post summary

    CVE‑2025‑36911 is a critical Fast Pair flaw that allows device hijacking without user interaction and has been disclosed; firmware updates are required for mitigation.

    0000051
    8.1M followersView on X
  • Grengo@spainfunk
    Disclosure

    🚨 تحذير خطير لمستعملي سماعات البلوتوث 🚨 كاينة ثغرة أمنية جديدة CVE-2025-36911 كتهم طريقة الربط ديال بعض أجهزة البلوتوث. هاد الثغرة كتخلّي أي واحد قريب منك يقدر: 🎧 يسمع شنو كتسمع فالسماعة ديالك ❌ يقطع ليك اتصال البلوتوث 🔊 ويدخل أي صوت ويتسمّع ليك بلا ما تحس 🛑 شنو تدير دابا؟ طفي البلوتوث إلا ما محتاجوش خرج السماعات من وضع الاقتران (Pairing) ملي تسالي ما تستعملش السماعات فالأماكن العامة إلا للضرورة

    Post summary

    A newly disclosed Bluetooth pairing vulnerability (CVE-2025-36911) can let nearby attackers eavesdrop, disconnect, and inject audio; users should disable Bluetooth or exit pairing mode to mitigate the risk.

    0000075
    500 followersView on X
  • Abhinav Yadav@Raging_Wolfie
    Disclosure

    Just published a technical breakdown of Google Fast Pair and the WhisperPair vulnerability (CVE-2025-36911). Learn how static Fast Pair BLE advertisements enable passive tracking and why this matters for device privacy. Full article: https://medium.com/@IRONmanABHI/googles-fast-pair-vulnerability-how-whisperpair-lets-hackers-hijack-bluetooth-devices-4ebb7395ab9d https://t.co/mpiLcKeAgi

    Post summary

    The article presents a technical breakdown of the Google Fast Pair WhisperPair vulnerability (CVE-2025-36911), explaining how static BLE advertisements enable passive device tracking.

    0000066
    6 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid---

Explore more