Blog

A Worse Kind of Earworm

Belgian researchers discovered that over a dozen earphone models using Google's Fast Pair protocol are vulnerable to WhisperPair attacks, potentially allowing hackers to hijack audio, track locations, and eavesdrop on users.

Earphones have become a ubiquitous part of our daily lives. Who hasn’t shut out the world by sticking these technological marvels in their ears, cranking the volume of their favorite song, and drowning out the noise? Unfortunately, Belgian researchers have discovered that these little havens from everyday drudgery could cause more harm than just getting a song stuck in your head. They determined that over a dozen earphone models were vulnerable to a pretty nasty cyberattack, all because of a feature that prioritized convenience over security.

The Flaw

Last August, researchers from Belgium’s KU Leuven University Computer Security and Industrial Cryptography group developed a hacking technique they dubbed WhisperPair. This hack takes advantage of several vulnerabilities present in the Fast Pair wireless protocol, a convenience feature that allows users to connect their Bluetooth gadgets, such as earphones or headphones, with Android and ChromeOS devices in a single tap. The researchers found that of the audio accessory models that use the Fast Pair protocol, 17 of them were vulnerable to WhisperPair exploitation. These models aren’t uncommon either, hundreds of millions of people have audio accessories vulnerable to the WhisperPair exploit.

The conditions needed to exploit this flaw aren’t particularly difficult to meet either. A hacker only needs to have a target device’s Model ID value and to be within 50 feet of the device for 10 seconds-no special hardware is required. While the Model ID is specific to a device model, hackers could obtain a device’s ID fairly easily if they own the same device model or if the target device shares the ID during pairing attempts. But even if both of these methods fail, a hacker could still find the desired Model ID by querying a publicly available Google API.

Fundamentally, the key flaw each of these 17 devices have is that, in spite of Fast Pair’s specifications, they allow a second device to silently pair with a Bluetooth gadget already paired with a device. Depending on the accessory, a hacker that pairs with a device in this way could then take over or disrupt audio streams and phone conversations, play their own audio through the device at a volume they choose, or listen to the victim’s surroundings via the device’s microphone. But vulnerable devices that support Google’s Find Hub, a feature that helps users find their lost gadgets, are of the most concern.

If a device with Find Hub is the target of a WhisperPair exploit, a hacker could potentially gain access to the user’s location at all times. This is only possible if the user hasn’t linked their device to a Google account, which is automatically done when paired with an Android device. But if the user has another brand of device, such as an iPhone, the hacker can link the target device to their own Google account, allowing them to track the device’s location. From then on, so long as a victim has their Bluetooth device on hand, the hacker can stalk them.

Mitigation

Addressing this flaw is easier said than done because owners of Internet-of-Things devices, such as earphones, don’t often update them. Updating such devices often requires the owner to use a manufacturing app they may have never downloaded since purchasing the device, meaning gadgets vulnerable to WhisperPair could go unpatched for months or even years. If you’re concerned that WhisperPair might impact one of your Bluetooth devices, you can check if your device is vulnerable here. Consumers should find out how to update impacted devices so they can receive WhisperPair patches as they develop.

However, patching results across the 10 companies selling affected devices have been mixed. Some companies haven’t responded to requests for comments, while others, like Google, have already released patches for the issue. Notably, however, Google’s patch for the Find Hub tracking flaw was initially ineffective, as the KU Leuven researchers found a way to bypass it in just a few hours.

Additionally, simply adjusting the settings of a vulnerable accessory isn’t enough either, as there isn’t a way to turn off Fast Pair. An attacker’s access could be cleared from the device through a factory reset, though that doesn’t do anything to prevent the hacker from reconnecting with it.

What This Means

On the subject of WhisperPair’s impact, the KU Leuven researchers had this to say:

“WhisperPair is not an isolated issue. Our study shows that multiple devices, vendors, and chipsets are affected. These vulnerable devices passed both the manufacturers’ quality assurance tests and Google’s certification process, demonstrating a systemic failure rather than an individual developer error. While there is a certification process that devices must undergo before the Fast Pair functionality is activated, insecure implementations still reached the market at scale. This shows a chain of compliance failures in Google Fast Pair, as the vulnerability failed to be detected on all three levels: implementation, validation, and certification.”

At the end of the day, the WhisperPair attack came about because Fast Pair’s priority was convenience and not security. As Andy Greenberg and Lily Hay Newman from Wired put it, “the Bluetooth protocol itself contained none of the vulnerabilities [the researchers] discovered-only the one-tap protocol Google built on top of it to make pairing more convenient.”

While convenience can lead to more efficient systems in your company, it should always come second to the security that protects your employees, co-workers, and customers. If you’re concerned that convenience and security aren’t properly balanced at your company, Crimson Vista offers several services that can help you find out. We offer tools like Traceback to help you better understand the source code your company works with, SecurityHub to augment your cybersecurity teams, and much more. We’ll help you find the most convenient solutions to your problems without compromising the cybersecurity your company needs.

Sources

Continue

Keep reading.