One Tap to Hijack Them All: A Security Analysis of the Google Fast Pair Protocol
Sayon Duttagupta, Seppe Wyns, Nikola Antonijevic, Dave Singelée, Bart Preneel
摘要
Google's Fast Pair Service (GFPS) extends Bluetooth pairing with one-tap setup and account synchronisation. This paper presents the first comprehensive security analysis of GFPS. By examining 25 commercial accessories from 16 vendors across 17 unique Bluetooth chipsets, we uncover systemic enforcement failures of the specification's core security requirements. Moreover, we show that the security failures we have identified in the pairing protocol can be further cascaded, amplifying their impact across the device ecosystem. Although GFPS and Google's Find Hub network are often treated as distinct services within the broader Google ecosystem, we show that failures in one can produce severe consequences in the other. We demonstrate WhisperPair, a family of practical attacks that enables unauthorised pairing, silent hijacking of audio devices, and covert account binding that registers a victim's accessory to an attacker's account, thereby enabling persistent location tracking and stalking via Google Find Hub. These vulnerabilities are not isolated incidents but symptoms of systemic, ecosystem-wide gaps in implementation, validation, and certification. Our analysis exposes that the source of these flaws lies in GFPS's reliance on fallible, application-layer state checks rather than on cryptographic enforcement, allowing them to propagate across vendors to the end users. To address the root cause, we propose IntentPair, a lightweight protocol modification that cryptographically binds the user's pairing intent into the key schedule, eliminating the vulnerability by design. Our findings show how a small usability “add-on” can introduce large-scale security and privacy risks for hundreds of millions of users.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Provable Security Analyses of Google's and Apple's Bluetooth Fast Pair ProtocolsAlexandra Boldyreva, Olga Sanina, Roy StracovskyCRYPTO 2026
- Rediscovering Method Confusion in Proposed Security Fixes for BluetoothMaximilian von Tschirschnitz, Ludwig Peuckert, Moritz Buhl, Jens GrossklagsNDSS 2025
- BLUFFS: Bluetooth Forward and Future Secrecy Attacks and DefensesDaniele AntonioliCCS 2023 · 被引用 7 次
- Extrapolating Formal Analysis to Uncover Attacks in Bluetooth Passkey Entry PairingMohit Kumar Jangid, Yue Zhang, Zhiqiang LinNDSS 2023
- Snatcher: Apple Find My Network Exposes Your Lost Devices To StrangersZhenyu Ren, Yanbo Zhang, Boya Liu, Mo LiCCS 2026
