Junglewise Threat Intelligence

CVE-2026-89034: TCH QRing smart ring Bluetooth authentication bypass

CVE-2026-89034 · Severity: medium · CVSS 6.5 · Published 2026-09-16

Executive brief

TCH QRing is a popular smart ring worn on the finger that tracks health metrics like heart rate and blood oxygen levels. A flaw in its Bluetooth design allows attackers nearby to connect directly to the ring without any PIN, pairing, or approval, bypassing the official app entirely. An attacker could read battery status, current heart rate, and retrieve months of stored health history—creating privacy risks and enabling physical surveillance of device owners.

Technical details

The vulnerability is an authentication bypass in the Nordic UART Service exposed over Bluetooth Low Energy (BLE). The service enforces no client authentication or command authorization, allowing any nearby device to connect without pairing PIN validation, session authentication, or device binding verification. An attacker within BLE range (typically 10–100 meters, depending on environment) can interact with the ring using custom clients, bypassing the official application and cloud authentication layer. Successful exploitation permits reading real-time battery status, activating live heart rate monitoring, and retrieving historical heart rate and blood oxygen records stored locally on the device. The Nordic UART Service implementation is vulnerable by design; no firmware patches are known to remediate this in the affected model and firmware version.

Affected products

  • TCH QRing model R20_B006 with firmware RT09R20_1.00.00_250318

Timeline

  • 2026-05-19: disclosed: Security research published by Mrvar0x on reverse engineering QRing ecosystem
  • 2026-09-16: advisory: CVE-2026-89034 published on NVD

References