Junglewise Threat Intelligence

CVE-2026-67568: Mira Android App data access vulnerability

CVE-2026-67568 · Severity: critical · CVSS 9.1 · Published 2026-08-11

Technologies: Quanovate Tech Inc. Mira Monitor Firmware, Quanovate Tech Inc. Mira Android App. Vendors: Quanovate Tech Inc..

Executive brief

Mira is a fertility and hormone tracking application used by consumers to monitor reproductive health through a companion wearable device. A critical vulnerability in the Android app version 4.5.15.4 allows attackers on a local network to read and modify sensitive health profile data without authentication, enabling attackers to alter medical records, impersonate users, or disrupt fertility tracking.

Technical details

The Mira Android app v4.5.15.4 relies on insecure device pairing mechanisms, using only substring matching of BLE advertisement names without cryptographic authentication, MAC allowlists, or bonded-identity verification. This authentication bypass allows attackers within Bluetooth range (approximately 10–30 meters) to intercept session tokens and inject forged hormone measurements. An attacker can read/write reproductive health profiles from internet-connected hosts without credentials, leading to unauthorized disclosure, modification, and deletion of sensitive health information. Affected firmware version 1.7.1.47 compounds the issue by accepting unauthenticated BLE commands. Patches are available: Android v4.5.18 and Firmware v01.07.01.53.

Affected products

  • Quanovate Tech Inc. Mira Android App 4.5.15.4
  • Quanovate Tech Inc. Mira Monitor Firmware 1.7.1.47

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched: Android app v4.5.18, Firmware v01.07.01.53

References

Related threats