CVE-2026-67558 PUBLISHED

Mira Hormone Monitor, Mira Android App Authentication bypass by spoofing

Assigner: icscert
Reserved: 03.08.2026 Published: 11.08.2026 Updated: 11.08.2026

The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N
CVSS Score: 8.2

Product Status

Vendor Quanovate Tech Inc. (operating as Mira / Mira Care)
Product Mira Firmware
Versions Default: unaffected
  • Version 1.7.1.47 is affected
Vendor Quanovate Tech Inc. (operating as Mira / Mira Care)
Product Mira Android App
Versions Default: unaffected
  • Version 4.5.15.4 is affected

Solutions

Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.

Credits

  • Gigi Xiaoqing Liu, Muzzammil Mohammed, Narmina Karimova, and En Mong of Northeastern University SPQR Lab reported this vulnerability to Quanovate Tech. finder

References

Problem Types

  • CWE-290 CWE