Skip to content

Latest commit

ย 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

๐Ÿ“ก BLE Advertise

Spoof Bluetooth Low Energy devices and trigger real pairing popups on nearby phones.

BLE Advertise is an Android app that advertises fake Bluetooth Low Energy (BLE) devices so you can trigger the exact pairing notifications a real device would show โ€” Google Fast Pair, Apple AirPods, Samsung Galaxy Watch / Buds and Microsoft Swift Pair โ€” with one tap.

Build License Language Platform Min SDK

A clean-room, educational implementation of Bluetooth advertising spoofing โ€” 37 built-in device profiles, 4 spoofing protocols, and a CI-published APK.


๐Ÿ“– About

BLE advertising is just bytes in the air. When a phone's radio receives a well-formed advertisement that matches a known device signature, the operating system shows a pairing popup for that product โ€” even though no real device exists nearby.

BLE Advertise lets you broadcast those exact byte patterns from any Android phone. Pick a device, tap Start Advertising, and nearby phones will show the pairing notification for that product.

โš ๏ธ This is an educational and security-testing tool. Use it on your own devices, for demos, or to understand how BLE advertising works โ€” not to annoy or harass other people.

๐Ÿšซ What it does NOT do: a phone that merely sees (or even connects to) a BLE advertisement never grants the advertiser access to its microphone, speaker, storage, or personal data. Bluetooth simply does not work that way, and no app built like this one โ€” including this one โ€” can "extract data from a connected phone". Treat any app that claims this as a red flag.


โœจ Features

  • ๐ŸŽง Google Fast Pair โ€” Spoof Android Fast Pair devices (Pixel Buds, Sony, Bose, JBL, Beats, OnePlus, Xiaomi, realme, Jabra, soundcore, TicWatch, Fitbit, Galaxy โ€ฆ) using real 3-byte model IDs over service UUID 0xFE2C.
  • ๐ŸŽ Apple AirPods โ€” Spoof AirPods, AirPods 2nd/3rd Gen, AirPods Pro 1st/2nd Gen and AirPods Max via the Apple Continuity manufacturer-data protocol (0x004C).
  • โŒš Samsung Easy Setup โ€” Spoof Galaxy Watch 4/5/6 and Galaxy Buds 2 / Buds Live with the Samsung Easy Setup protocol (0x0075).
  • ๐Ÿ’ป Microsoft Swift Pair โ€” Spoof Swift Pair devices like the Xbox Controller and Surface line (0x0006).
  • ๐Ÿ” Foreground service โ€” Advertising keeps running with the screen off or the app backgrounded, via a specialUse foreground service.
  • ๐Ÿ’พ Persistent selection โ€” Your chosen device is remembered across restarts (START_STICKY service, SharedPreferences).
  • ๐Ÿ›ก๏ธ Runtime permissions โ€” Correct permission flows for Android 12+ (BLE) and legacy devices (location-based BLE).
  • โšก CI-built APK โ€” Every push to main produces a signed debug APK as a GitHub Actions artifact.

37 built-in device profiles across 4 spoofing protocols.

Category Protocol Profiles
Google Fast Pair Service UUID 0xFE2C 18
Apple Continuity Manufacturer 0x004C 6
Samsung Easy Setup Manufacturer 0x0075 10
Microsoft Swift Pair Manufacturer 0x0006 3

๐ŸŽฏ Problem

Modern phones make pairing almost invisible. When you bring a set of earbuds or a smartwatch near a phone, a popup appears instantly and pairing "just works".

But that magic is built on trust in bytes. Each brand publishes a recognizable advertising signature:

  • Google Fast Pair devices advertise a 3-byte model ID under service UUID 0xFE2C
  • Apple AirPods advertise an Apple Continuity packet under manufacturer ID 0x004C
  • Samsung watches and buds advertise an Easy Setup packet under manufacturer ID 0x0075
  • Microsoft devices advertise a Swift Pair packet under manufacturer ID 0x0006

Any phone that understands these signatures shows a pairing popup on sight โ€” without verifying that a real product is transmitting.

Why this matters: advertisement spoofing is a known research and security topic (see projects like Bluetooth-LE-Spam and Flipper Xtreme). Understanding how these popups are triggered is essential for security testing, awareness, and education about how much of "wireless pairing" is actually just pattern matching.


๐Ÿ’ก Solution

BLE Advertise packages this knowledge into a simple, one-tap Android app.

flowchart LR
    A[User picks a device] --> B[DeviceProfiles catalog]
    B --> C[AdvertisePayload built<br/>service UUID / manufacturer data]
    C --> D[BleAdvertiser]
    D --> E[Android startAdvertisingSet]
    E --> F[BLE radio broadcasts bytes]
    F --> G[Nearby phone sees a known<br/>signature and shows pairing popup]
Loading
  1. Choose a device from a curated catalog of 37 profiles.
  2. The app builds the raw advertisement bytes โ€” the exact Fast Pair model ID, Continuity packet, Easy Setup frame, or Swift Pair frame for that product.
  3. Android's BLE advertiser broadcasts them on a short advertising interval.
  4. Nearby phones recognize the signature and display the corresponding pairing notification.

๐Ÿ—๏ธ Architecture

A minimal, clean Kotlin architecture built on Android's AdvertisingSet API (API 26+).

flowchart TB
    subgraph UI Layer
        A[MainActivity<br/>device list + permissions]
    end
    subgraph Service Layer
        B[AdvertisementForegroundService<br/>specialUse foreground service]
    end
    subgraph Core Layer
        C[BleAdvertiser]
        D[DeviceProfiles catalog]
        E[AdvertisePayload model]
        F[HexUtils]
    end
    subgraph Platform
        G[BluetoothLeAdvertiser<br/>startAdvertisingSet]
    end
    A --> B
    B --> C
    B --> D
    D --> E
    E --> C
    C --> G
    F --> D
    F --> E
Loading

Components

Component Responsibility
MainActivity Renders the device catalog, requests runtime permissions, and starts/stops advertising.
AdvertisementForegroundService A specialUse foreground service that keeps advertising alive with the screen off, restores state on restart, and shows a status notification with a Stop action.
BleAdvertiser Thin wrapper around BluetoothLeAdvertiser.startAdvertisingSet() with legacy-mode, non-connectable parameters.
DeviceProfiles The static catalog of 37 spoofable devices, encoding each protocol's byte layout.
AdvertisePayload Immutable data model describing a single advertisement (service UUID/data, manufacturer data, scan response).
HexUtils Hex string โ‡„ ByteArray helpers used to define payloads.

๐Ÿ› ๏ธ Tech Stack

Technology Purpose
Kotlin Primary language (JVM target 17)
Android SDK 35 compileSdk / targetSdk
minSdk 26 Supports Android 8.0 and above
Material 3 Modern UI (Theme.Material3.DayNight)
AndroidX core-ktx 1.15.0, appcompat 1.7.0
Material Components material 1.12.0
Android Gradle Plugin 8.7.3
Gradle 8.9
GitHub Actions Automated APK build on every push

๐Ÿ“‚ Project Structure

BLE-Advertise/
โ”œโ”€โ”€ .github/
โ”‚   โ””โ”€โ”€ workflows/
โ”‚       โ””โ”€โ”€ build-apk.yml          # CI: builds & publishes the debug APK
โ”œโ”€โ”€ app/
โ”‚   โ”œโ”€โ”€ build.gradle.kts           # Module config (SDK 35, Kotlin 17, deps)
โ”‚   โ”œโ”€โ”€ proguard-rules.pro
โ”‚   โ””โ”€โ”€ src/main/
โ”‚       โ”œโ”€โ”€ AndroidManifest.xml    # BLE + foreground-service permissions
โ”‚       โ”œโ”€โ”€ java/com/kamalesh/bleadvertise/
โ”‚       โ”‚   โ”œโ”€โ”€ MainActivity.kt                # UI + device selection
โ”‚       โ”‚   โ”œโ”€โ”€ AdvertisementForegroundService.kt
โ”‚       โ”‚   โ”œโ”€โ”€ BleAdvertiser.kt               # startAdvertisingSet wrapper
โ”‚       โ”‚   โ”œโ”€โ”€ DeviceProfiles.kt              # 37-device catalog
โ”‚       โ”‚   โ”œโ”€โ”€ DeviceProfile.kt               # Profile model
โ”‚       โ”‚   โ”œโ”€โ”€ AdvertisePayload.kt            # Advertisement data model
โ”‚       โ”‚   โ””โ”€โ”€ HexUtils.kt                    # Hex helpers
โ”‚       โ””โ”€โ”€ res/
โ”‚           โ”œโ”€โ”€ layout/activity_main.xml
โ”‚           โ”œโ”€โ”€ values/ (strings, colors, themes)
โ”‚           โ””โ”€โ”€ drawable/ + mipmap-anydpi-v26/
โ”œโ”€โ”€ build.gradle.kts               # Root build (AGP + Kotlin plugins)
โ”œโ”€โ”€ gradle.properties
โ”œโ”€โ”€ gradle/wrapper/gradle-wrapper.properties
โ”œโ”€โ”€ settings.gradle.kts
โ”œโ”€โ”€ LICENSE                        # MIT
โ””โ”€โ”€ README.md

Key directories: java/com/kamalesh/bleadvertise/ holds all application logic, res/ holds the UI resources, and .github/workflows/ contains the CI pipeline.


โš™๏ธ Installation

Prerequisites

Requirement Version / Notes
JDK 17 or newer (Temurin recommended)
Gradle 8.9 (or use Android Studio's wrapper)
Android SDK platforms;android-35, build-tools;34.0.0 + 35.0.0
Android Studio Optional โ€” recommended for IDE support

Clone

git clone https://github.com/kamalesh4044/BLE-Advertise.git
cd BLE-Advertise

Build from the command line

# From the project root
gradle assembleDebug --no-daemon

The APK is written to:

app/build/outputs/apk/debug/app-debug.apk

Build in Android Studio

  1. Open the project folder in Android Studio.
  2. Android Studio will download the Gradle wrapper distribution automatically.
  3. Run the app configuration or build via Build โ†’ Build APK(s).

๐Ÿ”‘ No secrets required. This project has no API keys or environment variables โ€” clone, build, run.


โ–ถ๏ธ Usage

  1. Install the APK on an Android device (Android 8.0+ with Bluetooth LE support).
  2. Launch the app โ€” grant the requested permissions (Bluetooth, notifications, and location on Android 11 or older).
  3. Select a device from the catalog, grouped by protocol:
    • Google Fast Pair (Android) โ€” 18 profiles
    • Apple Continuity (AirPods) โ€” 6 profiles
    • Samsung Easy Setup โ€” 10 profiles
    • Microsoft Swift Pair (Windows) โ€” 3 profiles
  4. Tap Start Advertising.
  5. Bring the phone near another phone โ€” it will show the matching pairing popup.
  6. Tap Stop Advertising (or the notification's Stop action) when done.

๐Ÿ’ก Advertising runs in a foreground service, so it continues even if you lock the screen or open another app. Your selected device is remembered the next time you open the app.


๐Ÿ–ฅ๏ธ Screenshots / Demo

๐Ÿ“ท Screenshots are not yet included in this repository. A dedicated media section is planned โ€” see the Roadmap.

No live demo is hosted โ€” this is a native Android app intended to run on a physical device.


๐Ÿงช Testing

There is no automated test suite in this repository yet. The project currently relies on manual device testing (build โ†’ install โ†’ advertise โ†’ observe the popup on a second phone).

Automated unit/instrumentation tests are planned โ€” see the Roadmap.

โœ… The project is continuously verified for compilation: every push to main runs gradle assembleDebug in CI.


๐Ÿ” Security & Responsible Use

  • Spoofing is about awareness. This project demonstrates how pairing popups are triggered. Use it on devices you own or control.
  • It cannot harm other phones. A BLE advertisement is a one-way broadcast. The receiving phone does not expose its microphone, camera, storage, or data to the advertiser โ€” ever.
  • Permissions are the minimum required by the platform for BLE advertising and foreground-service operation; no data is collected, transmitted, or stored by this app beyond your locally saved device preference.
  • No secrets, ever. This repository contains no credentials. Never commit API keys, tokens, or secrets to any repository.

๐Ÿ—บ๏ธ Roadmap

โœ… Completed

  • Fast Pair spoofing (18 profiles)
  • Apple Continuity / AirPods spoofing (6 profiles)
  • Samsung Easy Setup watch & buds spoofing (10 profiles)
  • Microsoft Swift Pair spoofing (3 profiles)
  • Foreground-service advertising with persistent state
  • Runtime permission handling for all supported Android versions
  • CI pipeline that builds and publishes a debug APK

๐Ÿ”ฎ Planned (not yet implemented โ€” proposals welcome)

  • Custom payload editor (craft arbitrary service/manufacturer data)
  • Advertising interval & TX power controls
  • Rotation / cycling through multiple devices automatically
  • Automated unit + instrumentation tests
  • Screenshots and an in-app "About" page
  • Release signing configuration

๐Ÿค Contributing

Contributions are welcome! To get started:

  1. Fork the repository.
  2. Create a branch โ€” git checkout -b feature/your-feature.
  3. Make your changes โ€” follow the existing Kotlin style and structure.
  4. Verify the build โ€” gradle assembleDebug must pass.
  5. Commit โ€” with a clear, descriptive message.
  6. Push โ€” git push origin feature/your-feature.
  7. Open a Pull Request โ€” describe the change and how you tested it.

Ideas are welcome too โ€” open an issue for bugs, feature requests, or new device profiles.


๐Ÿ“œ License

This project is licensed under the MIT License โ€” see LICENSE for details.

Device model IDs and advertisement formats are referenced from the public Google Fast Pair ecosystem and the open-source Flipper Xtreme BLE Spam / Bluetooth-LE-Spam projects. BLE Advertise is an independent, clean-room implementation written for educational purposes.


๐Ÿ‘จโ€๐Ÿ’ป Author

Kamalesh โ€” created and maintained by kamalesh4044.


โญ Support

If you find this project useful or interesting:

  • โญ Star the repository to show support
  • ๐Ÿ› Report issues โ€” bug reports and feature requests are welcome
  • ๐Ÿš€ Contribute โ€” new profiles and protocols are especially valuable
  • ๐Ÿ’ฌ Share feedback โ€” constructive feedback improves the project

Bluetooth pairing popups are just pattern matching over the air. Understanding that โ€” by reading the bytes, building the packets, and testing your own devices โ€” is how the next generation of wireless developers learns to build better, safer proximity experiences.

Learn. Test. Build. ๐Ÿš€

About

Advertise fake BLE devices from Android to trigger Fast Pair, AirPods, Samsung & Swift Pair pairing popups on nearby phones. Educational and security-testing use only.

Topics

Resources

Stars

10 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages