BLE Advertise is an Android app that advertises fake Bluetooth Low Energy (BLE) devices so you can trigger the exact pairing notifications a real device would show โ Google Fast Pair, Apple AirPods, Samsung Galaxy Watch / Buds and Microsoft Swift Pair โ with one tap.
A clean-room, educational implementation of Bluetooth advertising spoofing โ 37 built-in device profiles, 4 spoofing protocols, and a CI-published APK.
BLE advertising is just bytes in the air. When a phone's radio receives a well-formed advertisement that matches a known device signature, the operating system shows a pairing popup for that product โ even though no real device exists nearby.
BLE Advertise lets you broadcast those exact byte patterns from any Android phone. Pick a device, tap Start Advertising, and nearby phones will show the pairing notification for that product.
โ ๏ธ This is an educational and security-testing tool. Use it on your own devices, for demos, or to understand how BLE advertising works โ not to annoy or harass other people.
๐ซ What it does NOT do: a phone that merely sees (or even connects to) a BLE advertisement never grants the advertiser access to its microphone, speaker, storage, or personal data. Bluetooth simply does not work that way, and no app built like this one โ including this one โ can "extract data from a connected phone". Treat any app that claims this as a red flag.
- ๐ง Google Fast Pair โ Spoof Android Fast Pair devices (Pixel Buds, Sony, Bose, JBL, Beats, OnePlus, Xiaomi, realme, Jabra, soundcore, TicWatch, Fitbit, Galaxy โฆ) using real 3-byte model IDs over service UUID
0xFE2C. - ๐ Apple AirPods โ Spoof AirPods, AirPods 2nd/3rd Gen, AirPods Pro 1st/2nd Gen and AirPods Max via the Apple Continuity manufacturer-data protocol (
0x004C). - โ Samsung Easy Setup โ Spoof Galaxy Watch 4/5/6 and Galaxy Buds 2 / Buds Live with the Samsung Easy Setup protocol (
0x0075). - ๐ป Microsoft Swift Pair โ Spoof Swift Pair devices like the Xbox Controller and Surface line (
0x0006). - ๐ Foreground service โ Advertising keeps running with the screen off or the app backgrounded, via a
specialUseforeground service. - ๐พ Persistent selection โ Your chosen device is remembered across restarts (
START_STICKYservice,SharedPreferences). - ๐ก๏ธ Runtime permissions โ Correct permission flows for Android 12+ (BLE) and legacy devices (location-based BLE).
- โก CI-built APK โ Every push to
mainproduces a signed debug APK as a GitHub Actions artifact.
37 built-in device profiles across 4 spoofing protocols.
| Category | Protocol | Profiles |
|---|---|---|
| Google Fast Pair | Service UUID 0xFE2C |
18 |
| Apple Continuity | Manufacturer 0x004C |
6 |
| Samsung Easy Setup | Manufacturer 0x0075 |
10 |
| Microsoft Swift Pair | Manufacturer 0x0006 |
3 |
Modern phones make pairing almost invisible. When you bring a set of earbuds or a smartwatch near a phone, a popup appears instantly and pairing "just works".
But that magic is built on trust in bytes. Each brand publishes a recognizable advertising signature:
- Google Fast Pair devices advertise a 3-byte model ID under service UUID
0xFE2C - Apple AirPods advertise an Apple Continuity packet under manufacturer ID
0x004C - Samsung watches and buds advertise an Easy Setup packet under manufacturer ID
0x0075 - Microsoft devices advertise a Swift Pair packet under manufacturer ID
0x0006
Any phone that understands these signatures shows a pairing popup on sight โ without verifying that a real product is transmitting.
Why this matters: advertisement spoofing is a known research and security topic (see projects like Bluetooth-LE-Spam and Flipper Xtreme). Understanding how these popups are triggered is essential for security testing, awareness, and education about how much of "wireless pairing" is actually just pattern matching.
BLE Advertise packages this knowledge into a simple, one-tap Android app.
flowchart LR
A[User picks a device] --> B[DeviceProfiles catalog]
B --> C[AdvertisePayload built<br/>service UUID / manufacturer data]
C --> D[BleAdvertiser]
D --> E[Android startAdvertisingSet]
E --> F[BLE radio broadcasts bytes]
F --> G[Nearby phone sees a known<br/>signature and shows pairing popup]
- Choose a device from a curated catalog of 37 profiles.
- The app builds the raw advertisement bytes โ the exact Fast Pair model ID, Continuity packet, Easy Setup frame, or Swift Pair frame for that product.
- Android's BLE advertiser broadcasts them on a short advertising interval.
- Nearby phones recognize the signature and display the corresponding pairing notification.
A minimal, clean Kotlin architecture built on Android's AdvertisingSet API (API 26+).
flowchart TB
subgraph UI Layer
A[MainActivity<br/>device list + permissions]
end
subgraph Service Layer
B[AdvertisementForegroundService<br/>specialUse foreground service]
end
subgraph Core Layer
C[BleAdvertiser]
D[DeviceProfiles catalog]
E[AdvertisePayload model]
F[HexUtils]
end
subgraph Platform
G[BluetoothLeAdvertiser<br/>startAdvertisingSet]
end
A --> B
B --> C
B --> D
D --> E
E --> C
C --> G
F --> D
F --> E
| Component | Responsibility |
|---|---|
MainActivity |
Renders the device catalog, requests runtime permissions, and starts/stops advertising. |
AdvertisementForegroundService |
A specialUse foreground service that keeps advertising alive with the screen off, restores state on restart, and shows a status notification with a Stop action. |
BleAdvertiser |
Thin wrapper around BluetoothLeAdvertiser.startAdvertisingSet() with legacy-mode, non-connectable parameters. |
DeviceProfiles |
The static catalog of 37 spoofable devices, encoding each protocol's byte layout. |
AdvertisePayload |
Immutable data model describing a single advertisement (service UUID/data, manufacturer data, scan response). |
HexUtils |
Hex string โ ByteArray helpers used to define payloads. |
| Technology | Purpose |
|---|---|
| Kotlin | Primary language (JVM target 17) |
| Android SDK 35 | compileSdk / targetSdk |
| minSdk 26 | Supports Android 8.0 and above |
| Material 3 | Modern UI (Theme.Material3.DayNight) |
| AndroidX | core-ktx 1.15.0, appcompat 1.7.0 |
| Material Components | material 1.12.0 |
| Android Gradle Plugin | 8.7.3 |
| Gradle | 8.9 |
| GitHub Actions | Automated APK build on every push |
BLE-Advertise/
โโโ .github/
โ โโโ workflows/
โ โโโ build-apk.yml # CI: builds & publishes the debug APK
โโโ app/
โ โโโ build.gradle.kts # Module config (SDK 35, Kotlin 17, deps)
โ โโโ proguard-rules.pro
โ โโโ src/main/
โ โโโ AndroidManifest.xml # BLE + foreground-service permissions
โ โโโ java/com/kamalesh/bleadvertise/
โ โ โโโ MainActivity.kt # UI + device selection
โ โ โโโ AdvertisementForegroundService.kt
โ โ โโโ BleAdvertiser.kt # startAdvertisingSet wrapper
โ โ โโโ DeviceProfiles.kt # 37-device catalog
โ โ โโโ DeviceProfile.kt # Profile model
โ โ โโโ AdvertisePayload.kt # Advertisement data model
โ โ โโโ HexUtils.kt # Hex helpers
โ โโโ res/
โ โโโ layout/activity_main.xml
โ โโโ values/ (strings, colors, themes)
โ โโโ drawable/ + mipmap-anydpi-v26/
โโโ build.gradle.kts # Root build (AGP + Kotlin plugins)
โโโ gradle.properties
โโโ gradle/wrapper/gradle-wrapper.properties
โโโ settings.gradle.kts
โโโ LICENSE # MIT
โโโ README.md
Key directories: java/com/kamalesh/bleadvertise/ holds all application logic, res/ holds the UI resources, and .github/workflows/ contains the CI pipeline.
| Requirement | Version / Notes |
|---|---|
| JDK | 17 or newer (Temurin recommended) |
| Gradle | 8.9 (or use Android Studio's wrapper) |
| Android SDK | platforms;android-35, build-tools;34.0.0 + 35.0.0 |
| Android Studio | Optional โ recommended for IDE support |
git clone https://github.com/kamalesh4044/BLE-Advertise.git
cd BLE-Advertise# From the project root
gradle assembleDebug --no-daemonThe APK is written to:
app/build/outputs/apk/debug/app-debug.apk
- Open the project folder in Android Studio.
- Android Studio will download the Gradle wrapper distribution automatically.
- Run the
appconfiguration or build via Build โ Build APK(s).
๐ No secrets required. This project has no API keys or environment variables โ clone, build, run.
- Install the APK on an Android device (Android 8.0+ with Bluetooth LE support).
- Launch the app โ grant the requested permissions (Bluetooth, notifications, and location on Android 11 or older).
- Select a device from the catalog, grouped by protocol:
- Google Fast Pair (Android) โ 18 profiles
- Apple Continuity (AirPods) โ 6 profiles
- Samsung Easy Setup โ 10 profiles
- Microsoft Swift Pair (Windows) โ 3 profiles
- Tap Start Advertising.
- Bring the phone near another phone โ it will show the matching pairing popup.
- Tap Stop Advertising (or the notification's Stop action) when done.
๐ก Advertising runs in a foreground service, so it continues even if you lock the screen or open another app. Your selected device is remembered the next time you open the app.
๐ท Screenshots are not yet included in this repository. A dedicated media section is planned โ see the Roadmap.
No live demo is hosted โ this is a native Android app intended to run on a physical device.
There is no automated test suite in this repository yet. The project currently relies on manual device testing (build โ install โ advertise โ observe the popup on a second phone).
Automated unit/instrumentation tests are planned โ see the Roadmap.
โ The project is continuously verified for compilation: every push to
mainrunsgradle assembleDebugin CI.
- Spoofing is about awareness. This project demonstrates how pairing popups are triggered. Use it on devices you own or control.
- It cannot harm other phones. A BLE advertisement is a one-way broadcast. The receiving phone does not expose its microphone, camera, storage, or data to the advertiser โ ever.
- Permissions are the minimum required by the platform for BLE advertising and foreground-service operation; no data is collected, transmitted, or stored by this app beyond your locally saved device preference.
- No secrets, ever. This repository contains no credentials. Never commit API keys, tokens, or secrets to any repository.
- Fast Pair spoofing (18 profiles)
- Apple Continuity / AirPods spoofing (6 profiles)
- Samsung Easy Setup watch & buds spoofing (10 profiles)
- Microsoft Swift Pair spoofing (3 profiles)
- Foreground-service advertising with persistent state
- Runtime permission handling for all supported Android versions
- CI pipeline that builds and publishes a debug APK
- Custom payload editor (craft arbitrary service/manufacturer data)
- Advertising interval & TX power controls
- Rotation / cycling through multiple devices automatically
- Automated unit + instrumentation tests
- Screenshots and an in-app "About" page
- Release signing configuration
Contributions are welcome! To get started:
- Fork the repository.
- Create a branch โ
git checkout -b feature/your-feature. - Make your changes โ follow the existing Kotlin style and structure.
- Verify the build โ
gradle assembleDebugmust pass. - Commit โ with a clear, descriptive message.
- Push โ
git push origin feature/your-feature. - Open a Pull Request โ describe the change and how you tested it.
Ideas are welcome too โ open an issue for bugs, feature requests, or new device profiles.
This project is licensed under the MIT License โ see LICENSE for details.
Device model IDs and advertisement formats are referenced from the public Google Fast Pair ecosystem and the open-source Flipper Xtreme BLE Spam / Bluetooth-LE-Spam projects. BLE Advertise is an independent, clean-room implementation written for educational purposes.
Kamalesh โ created and maintained by kamalesh4044.
If you find this project useful or interesting:
- โญ Star the repository to show support
- ๐ Report issues โ bug reports and feature requests are welcome
- ๐ Contribute โ new profiles and protocols are especially valuable
- ๐ฌ Share feedback โ constructive feedback improves the project
Bluetooth pairing popups are just pattern matching over the air. Understanding that โ by reading the bytes, building the packets, and testing your own devices โ is how the next generation of wireless developers learns to build better, safer proximity experiences.
Learn. Test. Build. ๐