7 months ago

Hackers Can Hijack Earbuds to Spy

Hackers Can Hijack Earbuds to Spy
This is how hackers can hijack your earbuds to spy on you · indianexpress.com

Researchers found a flaw in a system called Fast Pair that lets hackers take over your earbuds or speakers.

This can happen if you're near a hacker, and they can use your devices to listen to you, play sounds, or even track where you are.

Big companies like Sony, Google, and others are fixing this problem, but it shows that making things easy to use can sometimes make them less safe.

The hackers don't need to be very close, and they can take over your device in just a few seconds.

Google says they're working on making it safer, and some companies have already started fixing the problem.

Key facts

Vulnerabilities Found In
Fast Pair wireless protocol
Affected Brands
Sony, Jabra, JBL, Marshall, Xiaomi, Nothing, OnePlus, Soundcore, Logitech, Google
Attack Range
50 feet
Attack Time
10-15 seconds
Potential Impacts
Disrupt conversations, inject audio, track location, listen to surroundings
Researchers
KU Leuven University Computer Security and Industrial Cryptography group
Google's Response
Confirmed vulnerabilities, no evidence of active exploitation, pushed security patches

Quotes

Nikola Antonijević

Researcher at KU Leuven University

“The attacker now owns this device and can basically do whatever he wants with it.”
indianexpress.com
“Yes, we want to make our life easier and make our devices function more seamlessly. Convenience doesn’t immediately mean less secure. But in pursuit of convenience, we should not neglect security.”
indianexpress.com

Sayon Duttagupta

Researcher at KU Leuven University

“You’re walking down the street with your headphones on, you’re listening to some music. In less than 15 seconds, we can hijack your device. Which means that I can turn on the microphone and listen to your ambient sound. I can inject audio. I can track your location.”
indianexpress.com

Google spokesperson

Representative of Google

“We are constantly evaluating and enhancing Fast Pair and Find Hub security.”
indianexpress.com

Xiaomi spokesperson

Representative of Xiaomi

“Xiaomi has been in communication with Google and other relevant parties and working with suppliers to roll out [over-the-air] updates. We have confirmed internally that the issue you referenced was caused by a non-standard configuration by chip suppliers in relation to the Google Fast Pair protocol.”
indianexpress.com

JBL spokesperson

Representative of JBL

“Google has advised JBL about potential security vulnerabilities that could impact devices including headphones and speakers. We have received the security patches from Google and the software will be updated via JBL apps over the next few weeks.”
indianexpress.com

Sources

Related news