7 months ago
Hackers Can Hijack Earbuds to Spy
Researchers found a flaw in a system called Fast Pair that lets hackers take over your earbuds or speakers.
This can happen if you're near a hacker, and they can use your devices to listen to you, play sounds, or even track where you are.
Big companies like Sony, Google, and others are fixing this problem, but it shows that making things easy to use can sometimes make them less safe.
The hackers don't need to be very close, and they can take over your device in just a few seconds.
Google says they're working on making it safer, and some companies have already started fixing the problem.
Vulnerabilities in Fast Pair protocol allow hackers to hijack audio devices from multiple brands.
Attackers can take control of devices within 50 feet, enabling them to listen, inject audio, or track location.
Affected brands include Sony, Jabra, JBL, Marshall, Xiaomi, Nothing, OnePlus, Soundcore, Logitech, and Google.
Google confirmed the vulnerabilities but stated no evidence of active exploitation outside research settings.
Manufacturers are rolling out security patches to address the issues.
- Who
- Security researchers from KU Leuven University
- What
- Discovered vulnerabilities in Fast Pair protocol allowing device hijacking
- Where
- Not specified
- When
- Not specified
- Why
- To highlight security risks in convenience-focused wireless protocols
Key facts
- Vulnerabilities Found In
- Fast Pair wireless protocol
- Affected Brands
- Sony, Jabra, JBL, Marshall, Xiaomi, Nothing, OnePlus, Soundcore, Logitech, Google
- Attack Range
- 50 feet
- Attack Time
- 10-15 seconds
- Potential Impacts
- Disrupt conversations, inject audio, track location, listen to surroundings
- Researchers
- KU Leuven University Computer Security and Industrial Cryptography group
- Google's Response
- Confirmed vulnerabilities, no evidence of active exploitation, pushed security patches
Quotes
Nikola Antonijević
Researcher at KU Leuven University
“The attacker now owns this device and can basically do whatever he wants with it.”
indianexpress.com
“Yes, we want to make our life easier and make our devices function more seamlessly. Convenience doesn’t immediately mean less secure. But in pursuit of convenience, we should not neglect security.”
indianexpress.com
Sayon Duttagupta
Researcher at KU Leuven University
“You’re walking down the street with your headphones on, you’re listening to some music. In less than 15 seconds, we can hijack your device. Which means that I can turn on the microphone and listen to your ambient sound. I can inject audio. I can track your location.”
indianexpress.com
Google spokesperson
Representative of Google
“We are constantly evaluating and enhancing Fast Pair and Find Hub security.”
indianexpress.com
Xiaomi spokesperson
Representative of Xiaomi
“Xiaomi has been in communication with Google and other relevant parties and working with suppliers to roll out [over-the-air] updates. We have confirmed internally that the issue you referenced was caused by a non-standard configuration by chip suppliers in relation to the Google Fast Pair protocol.”
indianexpress.com
JBL spokesperson
Representative of JBL
“Google has advised JBL about potential security vulnerabilities that could impact devices including headphones and speakers. We have received the security patches from Google and the software will be updated via JBL apps over the next few weeks.”
indianexpress.com





