Executive brief
The Mira hormone monitor is a wearable fertility-tracking device that stores sensitive hormone measurements and connects via Bluetooth to a mobile app. An unauthenticated attacker within Bluetooth range (10–30 meters) can seize control of the device, steal stored medical data in plaintext, disable it remotely, and track the wearer's location, compromising both privacy and the reliability of health data critical to fertility management.
Technical details
CVE-2026-66875 is a critical authentication bypass affecting Mira Monitor firmware 1.7.1.47 build 01070147. The device accepts remote Bluetooth Low Energy (BLE) commands from any central without cryptographic authentication, allowing an attacker within ~10–30 meters to rebind the device to a malicious account, extract hormone measurements in cleartext, trigger denial-of-service via malformed opcodes, and perform long-term user tracking via a static non-rotating BLE address. The vulnerability stems from missing authentication checks on critical Bluetooth operations. Exploitation requires only BLE range and no user interaction; no authentication or special privileges are needed. Patched firmware version 01.07.01.53 is available and deployed automatically when the app is updated to iOS v3.5.18 or Android v4.5.18.
Affected products
- Quanovate Tech Inc. Mira Monitor 1.7.1.47
- Quanovate Tech Inc. Mira Android App 4.5.15.4
Timeline
- 2026-08-11: disclosed: CISA ICS Medical Advisory ICSMA-26-223-01 published
- 2026-08-11: patched: Firmware v01.07.01.53 available; app update iOS v3.5.18 / Android v4.5.18 includes patch