CVE-2026-67558: Quanovate Tech Inc. Operating As Mira / Mira Care Mira Android App

High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.

The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.

Affected products

Published 2026-08-11. Last modified 2026-09-01.