⚠️ Malware / Trojaner / VirenHEAVYGRAM und CHOSEN BRICK: Telegram-gesteuerte Windows-Malware für Spionage(15.09.2026 um 19:56 Uhr)
📰 IT Security NachrichtenWegen ausbleidender Kundenaufträge Ruag könnte fast 50 Stellen streichen(15.09.2026 um 17:00 Uhr)
📰 IT Security NachrichtenRZ.Nord Cybersicherheit Patrick Jung - konsequent PR - Cision News(15.09.2026 um 17:31 Uhr)
📰 IT Security NachrichtenInnodata beruft Ex-NSA-Chef Michael Rogers in den Verwaltungsrat - Goldesel(15.09.2026 um 17:49 Uhr)
📰 IT Security NachrichtenDie Risiken der KI-Abhängigkeit in der Cybersicherheit. - Vietnam.vn(15.09.2026 um 18:42 Uhr)
📰 IT Security NachrichtenUS military confirms it launched space weapons into Earth’s orbit(15.09.2026 um 19:31 Uhr)
🕵️ SicherheitslückenIT Security News Hourly Summary 2026-09-15 20h : 16 posts(15.09.2026 um 20:00 Uhr)
📰 IT Security Nachrichten[UPDATE] [mittel] libpng: Mehrere Schwachstellen(14.09.2026 um 13:09 Uhr)
⚠️ Malware / Trojaner / VirenHEAVYGRAM und CHOSEN BRICK: Telegram-gesteuerte Windows-Malware für Spionage(15.09.2026 um 19:56 Uhr)
📰 IT Security NachrichtenWegen ausbleidender Kundenaufträge Ruag könnte fast 50 Stellen streichen(15.09.2026 um 17:00 Uhr)
📰 IT Security NachrichtenRZ.Nord Cybersicherheit Patrick Jung - konsequent PR - Cision News(15.09.2026 um 17:31 Uhr)
📰 IT Security NachrichtenInnodata beruft Ex-NSA-Chef Michael Rogers in den Verwaltungsrat - Goldesel(15.09.2026 um 17:49 Uhr)
📰 IT Security NachrichtenDie Risiken der KI-Abhängigkeit in der Cybersicherheit. - Vietnam.vn(15.09.2026 um 18:42 Uhr)
📰 IT Security NachrichtenUS military confirms it launched space weapons into Earth’s orbit(15.09.2026 um 19:31 Uhr)
🕵️ SicherheitslückenIT Security News Hourly Summary 2026-09-15 20h : 16 posts(15.09.2026 um 20:00 Uhr)
📰 IT Security Nachrichten[UPDATE] [mittel] libpng: Mehrere Schwachstellen(14.09.2026 um 13:09 Uhr)

🎥 IT Security Video 🕛 vor 20 Tagen 2 Min Lesezeit SECURITY-FEED
0

Black Hat Asia 2026 | WhisperPair: A Security Analysis of Google Fast Pair

↗ Quelle (YouTube · Black Hat)
🗣️ Stimme:
📺
YouTube · Black Hat
18 YouTube-Aufrufe
Google Fast Pair has promised "one-tap" Bluetooth onboarding and seamless account synchronisation across phones, laptops and tablets, since 2017. In practice, it has quietly become the default pairing path for modern earbuds, headphones and speakers across the Android ecosystem. Users trust that once an accessory is bonded, it will not suddenly attach to somebody else's phone without explicit consent.

This Briefing shows that this trust was misplaced. We will present WhisperPair, a family of attacks that let a nearby adversary hijack Fast Pair compatible accessories that are not in pairing mode, seize audio, activate microphones, and silently attach the victim's device to the attacker's Google account for long term location tracking and stalking. The trick is simple but devastating: although the Fast Pair specification requires accessories to reject unauthorised pairing requests, a wide range of chipsets and vendors fail to enforce this in practice.

Using only commodity hardware and standard Bluetooth stacks, we evaluated 25 commercial earbuds, headphones and speakers from 16 brands, covering what we believe to be all major audio manufacturers currently supporting Fast Pair. Most of them could be hijacked in under 15 seconds, and every vulnerable model that supported Google's Find Hub extension allowed covert account binding and stalking until factory reset.

The Briefing walks through the attack in live demos, dissects what went wrong in Google's compliance chain, and releases a practical test harness that defenders can run against their own products. We will close with our proposed solution: IntentPair, a drop in protocol hardening that cryptographically binds user intent into Fast Pair without sacrificing usability. Our findings will show how a small usability "add-on" can introduce large-scale security and privacy risks for hundreds of millions of users when intent is not cryptographically bound, and how to address this to avoid such mass-scale problems.

For further information about this work, please visit https://whisperpair.eu/

Seppe Wyns | PhD Student, DistriNet, KU Leuven
Sayon Duttagupta | Scientific Researcher, COSIC, KU Leuven
Nikola Antonijević | PhD Student, COSIC, KU Leuven
Dave Singelée | Associate Professor, DistriNet - Group T, KU Leuven
Bart Preneel | Professor, COSIC, KU Leuven

https://blackhat.com/asia-26/briefings/schedule/index.html#whisperpair-a-security-analysis-of-google-fast-pair-50553
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
HEAVYGRAM und CHOSEN BRICK: Telegram-gesteuerte Windows-Malware für Spionage
1 Quelle
Cyber Resilience Act: Warum Cybersicherheit zur Produkteigenschaft wird - MED-engineering
1 Quelle
Wegen ausbleidender Kundenaufträge Ruag könnte fast 50 Stellen streichen