CVE-2026-66875: Quanovate Tech Inc. Operating As Mira / Mira Care Mira Android App
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address that never rotates.
Affected products
- Quanovate Tech Inc. Operating As Mira / Mira Care Mira Android App: version 4.5.15.4 only
- Quanovate Tech Inc. Operating As Mira / Mira Care Mira Firmware: version 1.7.1.47 only
Published 2026-08-11. Last modified 2026-09-03.