A Bluetooth security research tool that exploits two unpatched attack primitives on devices advertising Google Fast Pair, extracting permanent BDADDR, performing L2CAP denial-of-service, and hijacking via SMP Just Works during stack recovery.

Stars

34

7-day growth

No data

Forks

1

Open issues

0

License

MIT

Last updated

2026-07-13

AI repository intelligence
FR-AI / ANALYSIS

Why it is worth attention

It demonstrates critical vulnerabilities that bypass the CVE-2025-36911 firmware patch, exposing identity address leakage at the BlueZ layer and an SMP authentication bypass during Bluetooth stack recovery after DoS.

Who it is for

  • Bluetooth security researchers
  • Embedded system developers
  • Penetration testers specializing in IoT
  • Vendors of Fast Pair accessories

Use cases

  • Authorized security auditing of Fast Pair devices
  • Academic research on Bluetooth Low Energy flaws
  • Product vulnerability assessment and patch verification
  • Training and demonstrations for wireless security courses

Strengths

  • Operates entirely outside the Fast Pair GATT protocol, making it immune to the CVE-2025-36911 firmware patch
  • Provides a fully documented three-stage attack with clear code flow and root-cause analysis
  • Supports multi-adapter parallel attacks for higher success probability
  • Includes persistent bond hijack that survives reboots and reconnections

Considerations

  • Linux-only with root privileges and BlueZ required
  • Stage 3 hijack success is timing-dependent and requires the target to be in an unresponsive state
  • Only targets devices advertising Google Fast Pair (service UUID fe2c) — not a general Bluetooth attack tool

README quick start

Installation

Description

Three-stage Bluetooth DoS attack & Hijack on Fast Pair devices via CVE-2025-36911 (no Ubertooth needed)

Related repositories

Similar projects matched by category, topics, and programming language.

lopopolo
Featured
lopopolo GitHub avatar

harness-engineering

Harness Engineering is a methodology for improving coding agent outputs by carefully crafting the environment around them—providing curated context, tools, and executable constraints that encode an organization’s nonfunctional requirements and cumulative lessons.

AI & Machine LearningAI Agents
2,390
slvDev
Featured
slvDev GitHub avatar

esp32-ai

A 28.9 million parameter language model runs on an $8 ESP32-S3 microcontroller entirely on-device, generating simple stories at about 9.5 tokens per second.

AI & Machine LearningLarge Language Models
1,960
littledivy
Featured
littledivy GitHub avatar

mimic

mimic captures traffic from any iOS or web app and automatically generates a Python client library that lets you call the app's API like a regular library.

AI & Machine Learning
1,482