PT-2026-3081 · Google · Google Fast Pair

CVE-2025-36911

·

Published

2026-01-15

·

Updated

2026-09-05

CVSS v3.1

7.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Google Fast Pair (affected versions not specified) Android OS kernel (affected versions not specified)
Description A logic error in the key-based pairing code of the Google Fast Pair protocol allows nearby attackers (within approximately 14 meters) to silently hijack vulnerable Bluetooth audio accessories, such as headphones, earbuds, and speakers. The flaw exists because affected accessories may accept pairing requests even when they are not in pairing mode, enabling an attacker to force a pairing in about 10 seconds without user interaction. This can lead to the unauthorized disclosure of protected information, including the eavesdropping of user conversations via built-in microphones, audio injection, and the potential for long-term location tracking by abusing Google Find Hub ownership keys. This issue affects hundreds of millions of devices across multiple brands.
Recommendations Apply vendor firmware updates for the affected Bluetooth accessories. At the moment, there is no information about a newer version that contains a fix for this vulnerability for the Android OS kernel.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00509
CVE-2025-36911

Affected Products

Google Fast Pair