CVE-2026-67558: Quanovate Tech Inc. Operating As Mira / Mira Care Mira Android App
High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.
The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.
Affected products
- Quanovate Tech Inc. Operating As Mira / Mira Care Mira Android App: version 4.5.15.4 only
- Quanovate Tech Inc. Operating As Mira / Mira Care Mira Firmware: version 1.7.1.47 only
Published 2026-08-11. Last modified 2026-09-01.