CVE-2025-36911
HIGH 7.1EPSS 7.3%
In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjacent) information disclosure of user's conversations and location with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVSS v3.1
- 7.1 HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N - EPSS
- 7.27% chance of exploitation in the next 30 days, 94th percentile
- Published
- 2026-01-15
- Updated
- 2026-01-28
Proof-of-concept exploits (12)
- xarlord/btsec-testtool0★ · 2026-08-30
- Athexblackhat/BLUE-SPY
- PentHertz/CVE-2025-36911-exploit
- PivotChip/FrostedFastPair
- SteamPunk424/CVE-2025-36911-Wisper_Pair_Target_Finder
- aalex954/whisperpair-poc-tool
- Bazskillz/WhisperPair-PoC
- ekomsSavior/whisper
- pira12/WhisperPair-PoC
- zr0n/zwhisper-android
- zr0n/zwhisper-linux
- zr0n/zwhisper-windows