Executive brief
The Mira Android app is a mobile companion for a Bluetooth hormone monitoring device used to track fertility. The app fails to cryptographically verify that a Bluetooth device claiming to be a Mira monitor is authentic, relying only on a simple name match. An attacker within Bluetooth range could impersonate the device to intercept session tokens, inject false hormone measurements into patient cloud records, and manipulate clinical data—potentially affecting medical decisions and compromising privacy.
Technical details
The vulnerability is an authentication bypass (CWE-290) due to inadequate BLE peripheral authentication. The Android app identifies the paired Mira hormone analyzer using only a substring match against the BLE advertisement name, without cryptographic validation, MAC address allowlisting, or bonded-identity verification. An unauthenticated attacker within BLE range (approximately 10–30 meters) can spoof the device identity and capture session tokens in cleartext or inject forged measurements. The attack requires adjacent network proximity but no user authentication, though user interaction is expected in the normal pairing flow. Patches are available in Mira Android App v4.5.18 and firmware v01.07.01.53.
Affected products
- Quanovate Tech Inc. (operating as Mira/Mira Care) Mira Android App 4.5.15.4
- Quanovate Tech Inc. (operating as Mira/Mira Care) Mira Monitor Firmware 1.7.1.47
Timeline
- 2026-08-11: disclosed: CISA ICSMA-26-223-01 published