CVE-2025-36911

HIGH

Android - Unauthenticated Information Disclosure via Key-Based Pairing Logic Error

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 13 public exploits for CVE-2025-36911. PoCs published by zalexdev, SpectrixDev, KULeuven-COSIC.

AI-analyzed exploit summary This repository contains a working proof-of-concept for CVE-2025-36911, a vulnerability in Google's Fast Pair protocol that allows unauthorized pairing and microphone access. The tool includes a BLE scanner, vulnerability tester, and exploit demonstration for authorized security testing.

Description

In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjacent) information disclosure of user's conversations and location with no additional execution privileges needed. User interaction is not needed for exploitation.

Exploits (13)

nomisec WORKING POC 652 stars
by zalexdev · poc
https://github.com/zalexdev/wpair-app

This repository contains a working proof-of-concept for CVE-2025-36911, a vulnerability in Google's Fast Pair protocol that allows unauthorized pairing and microphone access. The tool includes a BLE scanner, vulnerability tester, and exploit demonstration for authorized security testing.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Google Fast Pair Protocol implementations
No auth needed
Prerequisites: Android device with Bluetooth LE support · Nearby vulnerable Fast Pair device
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 61 stars
by SpectrixDev · poc
https://github.com/SpectrixDev/DIY_WhisperPair

This repository contains a proof-of-concept toolkit for CVE-2025-36911, a vulnerability in Google Fast Pair that allows unauthorized pairing with Bluetooth devices. The toolkit includes scanning, verification, and information gathering capabilities to identify vulnerable devices.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Google Fast Pair (various Bluetooth accessory models)
No auth needed
Prerequisites: Bluetooth adapter · Proximity to target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 39 stars
by KULeuven-COSIC · poc
https://github.com/KULeuven-COSIC/WhisperPair

This repository contains a functional exploit PoC for CVE-2025-36911, targeting vulnerabilities in the Google Fast Pair protocol. The code includes methods to test pairing state predicates, nonce reuse, and invalid curve attacks, demonstrating the ability to bypass security checks in Bluetooth pairing processes.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Google Fast Pair protocol implementations
No auth needed
Prerequisites: Bluetooth adapter · Proximity to target device · Target device with vulnerable Fast Pair implementation
devstral-2 · analyzed May 27, 2026 Full analysis →
nomisec WORKING POC 18 stars
by PentHertz · poc
https://github.com/PentHertz/CVE-2025-36911-exploit

This repository contains a Python-based exploit for CVE-2025-36911, a vulnerability in Google Fast Pair implementations that allows unauthorized pairing to Bluetooth audio devices. The tool includes scanning, testing, and exploitation capabilities, leveraging BLE and GATT protocols to bypass pairing restrictions.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Google Fast Pair implementations on various Bluetooth audio devices
No auth needed
Prerequisites: Bluetooth Low Energy (BLE) capable device · Proximity to target Bluetooth audio device
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 6 stars
by PivotChip · poc
https://github.com/PivotChip/FrostedFastPair

This PoC demonstrates an authentication bypass vulnerability (CVE-2025-36911) in devices supporting Fast Pair, allowing unauthorized pairing via a crafted KBP handshake. It includes hardware-specific implementation for ESP32 and detailed protocol exploitation steps.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Devices supporting Google Fast Pair (GFPS) with vulnerable KBP handshake implementation
No auth needed
Prerequisites: ESP32 device with BLE support · NimBLE-Arduino library · Physical proximity to target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER 4 stars
by Cedric-Martz · poc
https://github.com/Cedric-Martz/CVE-2025-36911_scan

This repository contains a Python-based scanner for CVE-2025-36911, which tests Bluetooth audio devices for unauthenticated L2CAP connections to audio profiles (A2DP/AVRCP) without prior pairing. It checks for open PSMs and Fast Pair service detection.

Classification
Scanner 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Bluetooth audio devices (A2DP/AVRCP profiles)
No auth needed
Prerequisites: Bluetooth adapter · Physical proximity to target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 3 stars
by aalex954 · poc
https://github.com/aalex954/whisperpair-poc-tool

WhisperPair-PoC-Tool is a Python-based security research tool that exploits CVE-2025-36911, a vulnerability in Google's Fast Pair ecosystem allowing unauthorized pairing bypass and Find My Device Network tracking exploitation. The tool demonstrates passive and active checks for vulnerable Bluetooth accessories.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Google Fast Pair (various manufacturer implementations)
No auth needed
Prerequisites: Bluetooth Low Energy (BLE) capable device · Proximity to target Fast Pair accessory
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by Athexblackhat · poc
https://github.com/Athexblackhat/BLUE-SPY

The repository contains a functional exploit framework for CVE-2025-36911, targeting Google's Fast Pair protocol via Bluetooth Low Energy (BLE). The code includes a terminal interface for scanning, exploiting, and interacting with vulnerable devices, with clear technical implementation details.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Google Fast Pair protocol (Bluetooth Low Energy)
No auth needed
Prerequisites: Bluetooth Low Energy (BLE) capable hardware · Proximity to target devices · Python dependencies (bleak, cryptography)
devstral-2 · analyzed Mar 11, 2026 Full analysis →
nomisec WORKING POC 1 stars
by ap425q · poc
https://github.com/ap425q/whisper-pair

This repository contains a Python-based scanner and tester for CVE-2025-36911, a vulnerability in Google Fast Pair that allows unauthorized pairing and potential tracking via the Find Hub network. The tool scans for vulnerable Bluetooth accessories and tests them for the WhisperPair attack.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Google Fast Pair (various manufacturer implementations)
No auth needed
Prerequisites: Bluetooth adapter supporting BLE · Linux with BlueZ · Python 3.8+
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by Athexhacker · poc
https://github.com/Athexhacker/BLUE-SPY

The repository contains a functional exploit framework for CVE-2025-36911, targeting Google's Fast Pair protocol via Bluetooth Low Energy. It includes interactive terminal interfaces for scanning, exploiting, and testing HFP connections, with clear technical implementation in Python.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Google Fast Pair protocol (Bluetooth Low Energy)
No auth needed
Prerequisites: Bluetooth Low Energy capable device · Proximity to target devices · Python dependencies (bleak, cryptography)
devstral-2 · analyzed Feb 20, 2026 Full analysis →
nomisec WRITEUP
by fa1sa1142 · poc
https://github.com/fa1sa1142/wpair-app

This repository provides a README for a tool called WPair, which is described as a defensive security research tool to demonstrate the CVE-2025-36911 vulnerability in Google's Fast Pair protocol. The README includes installation instructions, system requirements, and usage guidelines but does not contain any exploit code or technical details about the vulnerability itself.

Classification
Writeup 90%
Attack Type
Other
Complexity
N/a
Reliability
N/a
Target: Google's Fast Pair protocol (affected Bluetooth audio devices)
No auth needed
Prerequisites: Bluetooth-enabled device · WPair application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SUSPICIOUS
by fa1sa1142 · poc
https://github.com/fa1sa1142/fa1sa1142.github.io

The repository claims to provide a tool for detecting CVE-2025-36911 but contains no actual exploit code or technical details. It directs users to external downloads, which is a common tactic for malicious or deceptive repositories.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Google's Fast Pair protocol (Bluetooth audio devices)
No auth needed
Prerequisites: Bluetooth-capable device · Vulnerable Bluetooth audio device
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER
by SteamPunk424 · poc
https://github.com/SteamPunk424/CVE-2025-36911-Wisper_Pair_Target_Finder

This repository contains a passive Bluetooth Low Energy (BLE) scanner designed to detect devices potentially vulnerable to CVE-2025-36911 by identifying Google Fast Pair indicators. It does not exploit the vulnerability but scans for exposed devices using specific UUIDs and manufacturer IDs.

Classification
Scanner 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Devices using Google Fast Pair (version not specified)
No auth needed
Prerequisites: Bluetooth Low Energy (BLE) capable hardware · Python 3 with Bleak library
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 7.1
EPSS 0.0694
EPSS Percentile 93.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (1)
google/android
Published Jan 15, 2026
Tracked Since Feb 18, 2026