Your Headphones Could Be a Spy: Major Bluetooth Flaw Found in Sony, Anker, and More

Bluetooth headphones with security warning symbol

Your Bluetooth headphones might be secretly listening—and tracking—without you ever knowing.

Researchers from KU Leuven University identified WhisperPair vulnerabilities in Google’s Fast Pair protocol, affecting 17 of 25+ tested Bluetooth audio devices.

Exploits enable eavesdropping via mics, unauthorized audio playback, and location tracking via Google’s Find Hub network. Affected devices include Sony WH-1000XM4/XM5/XM6, Nothing Ear (a), OnePlus Nord Buds 3 Pro, and Anker Soundcore Liberty 4 NC. Other OEMs also had vulnerable models.

Google pushed firmware fixes to OEMs in September 2025 but an additional Find Hub patch was bypassed within hours by researchers using outdated firmware. A Google spokesperson said:

"We worked with these researchers to fix these vulnerabilities, and we have not seen evidence of any exploitation outside of this report’s lab setting,"

OnePlus responded similarly, with Spenser Blank stating:

"We take all security reports seriously... will take appropriate action."