Feed/CVE-2025-36911
CVE-2025-36911HIGHCVSS 7.1

CVE-2025-36911

Published Jan 15, 2026·Updated Jun 17, 2026

NVD Description

In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjacent) information disclosure of user's conversations and location with no additional execution privileges needed. User interaction is not needed for exploitation.

Public Exploits & PoCs14 found

PoC: WhisperPair

The official reference implementation & vulnerability verification of our attack WhisperPair (CVE-2025-36911) which affects Google's Fast Pair protocol

39

PoC: DIY_WhisperPair

Hijacking Bluetooth Accessories Using Google Fast Pair: WhisperPair CVE-2025-36911 Reference Implementation & Vulnerability Verification Toolkit

11

PoC: CVE-2025-36911-exploit

Exploit of the CVE-2025-36911 vulnerability in Python

2

PoC: whisper-pair-app

WhisperPair is a defensive security research tool that demonstrates the CVE-2025-36911 vulnerability in Google's Fast Pair protocol. This vulnerability affects millions of Bluetooth audio devices worldwide, allowing unauthorized pairing and potential microphone access without user consent.

1

PoC: CVE-2025-36911_scan

This script can be used to check if a Bluetooth device is vulnerable to CVE-2025-36911.

1

PoC: Whisper_Bully

Two-stage Bluetooth DoS attack on Fast Pair devices via CVE-2025-36911

PoC: BLUE-SPY

BLUE-SPY (Bluetooth Low Energy Universal Exploit - Security Penetration Testing) is a professional security assessment tool for analyzing CVE-2025-36911 vulnerabilities in Google's Fast Pair protocol implementation.

PoC: fa1sa1142.github.io

🛡️ Scan for CVE-2025-36911 vulnerabilities with WPair, a research tool designed for Android developers using Kotlin. Secure your applications effectively.

PoC: wpair-app

🔍 Scan and research CVE-2025-36911 vulnerabilities with WPair, a specialized tool for Android built in Kotlin, ensuring your applications remain secure.

PoC: whisperpair-poc-tool

A security research tool that identifies and demonstrates the CVE-2025-36911: Fast Pair Pairing Mode Bypass vulnerability

PoC: whisper-pair

A Vulnerablity Scanner for Whisper Pair (CVE-2025-36911)

PoC: FrostedFastPair

WhisperPair (CVE-2025-36911) POC for ESP32 device

PoC: whisper-pair

A Vulnerablity Scanner for Whisper Pair (CVE-2025-36911)

PoC: CVE-2025-36911-Wisper_Pair_Target_Finder-

This is not an exploit for CVE-2025-26911!!! This is a detector for finding potentially vulnerable devices! Only use on your own devices! I am not responsible for damages!

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free