CVE-2025-36911

HIGH

Google Android - Information Disclosure

Title source: rule

Description

In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjacent) information disclosure of user's conversations and location with no additional execution privileges needed. User interaction is not needed for exploitation.

Exploits (12)

nomisec WORKING POC 652 stars
by zalexdev · poc
https://github.com/zalexdev/wpair-app
nomisec WORKING POC 61 stars
by SpectrixDev · poc
https://github.com/SpectrixDev/DIY_WhisperPair
nomisec WORKING POC 18 stars
by PentHertz · poc
https://github.com/PentHertz/CVE-2025-36911-exploit
nomisec WORKING POC 6 stars
by PivotChip · poc
https://github.com/PivotChip/FrostedFastPair
nomisec SCANNER 4 stars
by Cedric-Martz · poc
https://github.com/Cedric-Martz/CVE-2025-36911_scan
nomisec WORKING POC 3 stars
by aalex954 · poc
https://github.com/aalex954/whisperpair-poc-tool
nomisec WORKING POC 1 stars
by Athexblackhat · poc
https://github.com/Athexblackhat/BLUE-SPY
nomisec WORKING POC 1 stars
by ap425q · poc
https://github.com/ap425q/whisper-pair
nomisec WORKING POC
by Athexhacker · poc
https://github.com/Athexhacker/BLUE-SPY
nomisec WRITEUP
by fa1sa1142 · poc
https://github.com/fa1sa1142/wpair-app
nomisec SUSPICIOUS
by fa1sa1142 · poc
https://github.com/fa1sa1142/fa1sa1142.github.io
nomisec SCANNER
by SteamPunk424 · poc
https://github.com/SteamPunk424/CVE-2025-36911-Wisper_Pair_Target_Finder

Scores

CVSS v3 7.1
EPSS 0.0001
EPSS Percentile 0.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Details

Status published
Products (1)
google/android
Published Jan 15, 2026
Tracked Since Feb 18, 2026