
أداة بحث أمنية تحدد وتوضح ثغرة CVE-2025-36911: Fast Pair Pairing Mode Bypass
غوص عميق في CVE-2025-36911 والفجوات الأمنية في نظام Fast Pair من Google
صُمم Google Fast Pair لجعل الإقران عبر Bluetooth سلسًا: انقر على إشعار وستتصل. ولكن ماذا يحدث عندما تصبح هذه التجربة السلسة مسؤولية أمنية؟ WhisperPair-PoC-Tool هي أداة بحث أمني تكشف عن فئتين حرجتين من الثغرات تؤثران على ملايين ملحقات Bluetooth: تجاوز الإقران غير المصرح به واستغلال شبكة العثور على جهازي (Find My Device Network).
توضح هذه التدوينة التفاصيل الفنية الداخلية للأداة WhisperPair-PoC-Tool، ونقاط الضعف في البروتوكول التي تستغلها، وما يعنيه ذلك لنظام ملحقات Bluetooth.
تنص مواصفات Google Fast Pair صراحةً على:
"إذا كان حقل المفتاح العام الاختياري موجودًا: إذا لم يكن الجهاز في وضع الإقران، فتجاهل الكتابة واخرج."
هذه هي البوابة الأمنية الحرجة. يجب أن تستجيب الأجهزة فقط لطلبات الإقران القائمة على المفتاح عندما يضع المستخدم الجهاز صراحةً في وضع الإقران (عادةً بالضغط على زر). وهذا يضمن نية المستخدم، فلا يمكنك الإقران مع سماعات شخص ما أثناء ارتدائها.
المشكلة: يتجاهل العديد من المصنعين هذا الفحص بالكامل. فهم يعالجون طلبات الإقران بغض النظر عن حالة وضع الإقران، مما يتيح:
تسمح شبكة العثور على جهازي (FMDN) من Google بتتبع ملحقات Bluetooth عبر شبكة أجهزة Android الجماعية. وهذا يتطلب مفتاح حساب، وهو مفتاح متماثل بطول 16 بايت يربط الجهاز بحساب Google.
المشكلة: غالبًا ما تقبل خاصية مفتاح الحساب عمليات الكتابة دون مصادقة:
قبل الخوض في الاستغلال، دعنا نفهم تدفق Fast Pair الشرعي:
┌─────────────────────────────────────────────────────────────┐
│ BLE Advertisement │
├─────────────────────────────────────────────────────────────┤
│ Service UUID: 0xFE2C (Fast Pair) │
│ Service Data: │
│ [Pairing Mode] → 3 bytes: Model ID only │
│ [Not Pairing] → 4+ bytes: 0x00 + Account Key Filter │
└─────────────────────────────────────────────────────────────┘
يكشف تنسيق الإعلان عن حالة الإقران:
Seeker (Phone) Provider (Accessory)
│ │
│───── GATT Connect ──────────────────────────>│
│ │
│───── Discover Services ─────────────────────>│
│<──── Service: 0xFE2C ────────────────────────│
│ │
│───── Enable Notifications (0xFE2C1234) ─────>│
│ │
│───── Write Key-Based Pairing Request ───────>│
│ [16-byte encrypted block] │
│ [64-byte ECDH Public Key] (optional) │
│ │
│ ┌────────────────────────────────────┐ │
│ │ SECURITY CHECK: │ │
│ │ If Public Key present AND │ │
│ │ device NOT in pairing mode: │ │
│ │ → IGNORE and EXIT │ │
│ │ Else: │ │
│ │ → Process request │ │
│ └────────────────────────────────────┘ │
│ │
│<──── Notification: Encrypted Response ───────│
│ [Provider's BR/EDR Address] │
│ │
│═══════ Bluetooth Classic Pairing ═══════════>│
تحدث الثغرة عندما تتخطى الأجهزة مربع "الفحص الأمني" بالكامل.
WhisperPair-PoC-Tool هي أداة بحث أمني مبنية بلغة Python على مكتبة Bleak BLE. تعمل بعدة مراحل:
┌────────────────────────────────────────────────────────────────┐
│ WhisperPair-PoC-Tool │
├────────────────────────────────────────────────────────────────┤
│ CLI Layer │
│ ├── Argument parsing (--target-name, --scan-duration) │
│ ├── TargetPolicy construction │
│ └── REPL initialization │
├────────────────────────────────────────────────────────────────┤
│ Discovery Engine │
│ ├── BLE scanning via Bleak │
│ ├── Advertisement parsing │
│ ├── Protocol detection (Fast Pair, FMDN, Swift Pair) │
│ └── Device fingerprinting (Model ID, OUI lookup) │
├────────────────────────────────────────────────────────────────┤
│ Check Engines │
│ ├── FastPairCheckEngine (passive advertisement analysis) │
│ ├── FastPairBypass (active CVE-2025-36911 testing) │
│ ├── FindHubCheckEngine (Account Key status detection) │
│ └── RiskScorer (composite vulnerability assessment) │
├────────────────────────────────────────────────────────────────┤
│ Connection Manager │
│ ├── GATT connect with MTU negotiation │
│ ├── Service/characteristic discovery │
│ ├── Read/Write/Notify operations │
│ └── Error handling and retry logic │
├────────────────────────────────────────────────────────────────┤
│ Exploitation Modules │
│ ├── ring_device() - Trigger locator sound │
│ ├── set_account_key() - Write Account Key │
│ └── Response parsing (BR/EDR address extraction) │
└────────────────────────────────────────────────────────────────┘
discovery.py)يستخدم الماسح دوال الاسترجاع الخاصة بـ Bleak لالتقاط إعلانات BLE:
async def _detection_callback(
self, device: BLEDevice, advertisement_data: AdvertisementData
) -> None:
"""Process each detected BLE advertisement."""
discovered = DiscoveredDevice(
address=device.address,
name=device.name or advertisement_data.local_name,
rssi=advertisement_data.rssi,
advertisement=self._convert_advertisement(advertisement_data),
first_seen=datetime.now(UTC),
last_seen=datetime.now(UTC),
)
self._devices[device.address] = discovered