EILMELDUNGEN LIVE
🕵️ Sicherheitslücken[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE(25.08.2026 um 02:00 Uhr)
🕵️ Reverse EngineeringReverse Engineering Windows Security Center(27.08.2026 um 08:24 Uhr)
🕵️ SicherheitslückenExploits and vulnerabilities in Q2 2026(26.08.2026 um 12:00 Uhr)
🕵️ SicherheitslückenUSN-8680-1: FFmpeg vulnerabilities(25.08.2026 um 22:01 Uhr)
🕵️ SicherheitslückenUSN-8659-3: Linux kernel (Azure) vulnerability(25.08.2026 um 22:14 Uhr)
🕵️ SicherheitslückenUSN-8643-4: Linux kernel vulnerabilities(25.08.2026 um 22:21 Uhr)
🕵️ SicherheitslückenUSN-8658-3: Linux kernel vulnerabilities(25.08.2026 um 22:27 Uhr)
🐧 Linux TippsUSN-8630-5: Linux kernel (Raspberry Pi) vulnerabilities(25.08.2026 um 23:12 Uhr)
🕵️ Sicherheitslücken[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE(25.08.2026 um 02:00 Uhr)
🕵️ Reverse EngineeringReverse Engineering Windows Security Center(27.08.2026 um 08:24 Uhr)
🕵️ SicherheitslückenExploits and vulnerabilities in Q2 2026(26.08.2026 um 12:00 Uhr)
🕵️ SicherheitslückenUSN-8680-1: FFmpeg vulnerabilities(25.08.2026 um 22:01 Uhr)
🕵️ SicherheitslückenUSN-8659-3: Linux kernel (Azure) vulnerability(25.08.2026 um 22:14 Uhr)
🕵️ SicherheitslückenUSN-8643-4: Linux kernel vulnerabilities(25.08.2026 um 22:21 Uhr)
🕵️ SicherheitslückenUSN-8658-3: Linux kernel vulnerabilities(25.08.2026 um 22:27 Uhr)
🐧 Linux TippsUSN-8630-5: Linux kernel (Raspberry Pi) vulnerabilities(25.08.2026 um 23:12 Uhr)

6 🕛 kürzlich 2 Min Lesezeit 11 Leser online ️ CVE-RADAR
0

Black Hat Asia 2026 | WhisperPair: A Security Analysis of Google Fast Pair

Cyber Threat & Vulnerability Dossier CVSS 7.5 HIGH EPSS 32.4%
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
️ Im CVE-Radar öffnen
↗ Quelle (YouTube · Black Hat)
🗣️ Stimme:
📺
YouTube · Black Hat
18 YouTube-Aufrufe
Google Fast Pair has promised "one-tap" Bluetooth onboarding and seamless account synchronisation across phones, laptops and tablets, since 2017. In practice, it has quietly become the default pairing path for modern earbuds, headphones and speakers across the Android ecosystem. Users trust that once an accessory is bonded, it will not suddenly attach to somebody else's phone without explicit consent.

This Briefing shows that this trust was misplaced. We will present WhisperPair, a family of attacks that let a nearby adversary hijack Fast Pair compatible accessories that are not in pairing mode, seize audio, activate microphones, and silently attach the victim's device to the attacker's Google account for long term location tracking and stalking. The trick is simple but devastating: although the Fast Pair specification requires accessories to reject unauthorised pairing requests, a wide range of chipsets and vendors fail to enforce this in practice.

Using only commodity hardware and standard Bluetooth stacks, we evaluated 25 commercial earbuds, headphones and speakers from 16 brands, covering what we believe to be all major audio manufacturers currently supporting Fast Pair. Most of them could be hijacked in under 15 seconds, and every vulnerable model that supported Google's Find Hub extension allowed covert account binding and stalking until factory reset.

The Briefing walks through the attack in live demos, dissects what went wrong in Google's compliance chain, and releases a practical test harness that defenders can run against their own products. We will close with our proposed solution: IntentPair, a drop in protocol hardening that cryptographically binds user intent into Fast Pair without sacrificing usability. Our findings will show how a small usability "add-on" can introduce large-scale security and privacy risks for hundreds of millions of users when intent is not cryptographically bound, and how to address this to avoid such mass-scale problems.

For further information about this work, please visit https://whisperpair.eu/

Seppe Wyns | PhD Student, DistriNet, KU Leuven
Sayon Duttagupta | Scientific Researcher, COSIC, KU Leuven
Nikola Antonijević | PhD Student, COSIC, KU Leuven
Dave Singelée | Associate Professor, DistriNet - Group T, KU Leuven
Bart Preneel | Professor, COSIC, KU Leuven

https://blackhat.com/asia-26/briefings/schedule/index.html#whisperpair-a-security-analysis-of-google-fast-pair-50553
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
134 Fachleser & IT-Security Experten haben diesen Report heute geteilt
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Community-Einschätzung (Live): 48 Stimmen
🟢 Gering: 45% 🟡 Beobachten: 35% 🔴 Akut: 20%

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 48%
🟡 In Evaluierung 26%
🟢 Keine Auswirkung 19%
Spannende Innovation 7%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
8 Quellen
USN-8659-3: Linux kernel (Azure) vulnerability
2 Quellen
USN-8680-1: FFmpeg vulnerabilities
1 Quelle
Exploits and vulnerabilities in Q2 2026