โ Back to Feed
Mira Hormone Monitor, Mira Android App
CVE-2026-66875CVE-2026-66098CVE-2026-67558CVE-2026-67568CVE-2026-68067CVE-2026-66340CVE-2026-64934CVE-2026-66832
August 11, 2026 ยท CISA (US-CERT) ยท Severity: CRITICAL
The Mira Hormone Monitor system contains eight critical vulnerabilities affecting both the hardware firmware (v1.7.1.47) and Android application (v4.5.15.4). These flaws enable unauthorized access to sensitive health data, account takeover, device rebinding to malicious actors, and user tracking through Bluetooth Low Energy (BLE) weaknesses. The vulnerabilities stem from authentication failures, hardcoded credentials, and improper input validation in security decisions. ๐ **Analyst Note:** Healthcare organizations using Mira devices should immediately isolate them from networks and await patching, as these vulnerabilities enable complete compromise of medical data integrity.
Key Takeaways
- Multiple critical vulnerabilities in Mira Hormone Monitor and Android App expose sensitive health data.
- Attackers can bypass authentication, hijack accounts, and manipulate hormone measurements without user interaction.
- The device's static BLE address enables persistent tracking of users within wireless range.
- Firmware and app updates are urgently required to mitigate these high-severity risks.