
WhisperPair (CVE-2025-36911) POC for ESP32 device
POC for CVE-2025-36911 WhisperPair vulnerability, allowing you to connect to supported devices with no authentication info.
This firmware only performs discovery and vulnerability confirmation and does not implement complete audio listening.
Output on during tests:
Tested on Device: Freenove ESP32-S3 ESP32 S3 Display CYD 2.8 Inch IPS Capacitive Touch Screen 240x320 Pixel
You can use ESP32 device to track down devices that support Fast Pair and check vulneravility.

Interested in penetration testing and security devices? Visit
The scanner (BleManager) bypasses standard discovery to parse raw advertisement packets for GFPS payloads
0xFE2C.0xFEF3.To handle privacy-enabled BLE devices that rotate MAC addresses, the system uses a tiered identity check
Model ID or Device Name.The testDevice function executes a raw GFPS handshake to test for unauthorized pairing acceptance
0xFE2C) and KBP Characteristic (fe2c1234-8366-4814-8eb0-01de32100bea).[Type: 0x00] [Flags: 0x11] [Provider Address] [Salt: 8 bytes].mbedtls_aes_crypt_ecb with the Salt as the key.config.h)Designed for ESP32 with FT6336U touch and TFT_eSPI displays .
| Function |
|---|
NimBLE-Arduino (2.3.7)TFT_eSPI (Display)FT6336U (Input)User_Setup.h in the TFT_eSPI library to match the ILI9341/ST7789 driver for your specific board.or download libraries from Freenove and place it into your Arduino Library folder
https://codeload.github.com/Freenove/Freenove_ESP32_S3_Display/zip/refs/heads/main
SCAN to populate the list.| Pin |
|---|
| Touch SDA | 16 |
| Touch SCL | 15 |
| Touch RST | 18 |
| Touch INT | 17 |