What is CVE-2026-67558?
This vulnerability exists in the Mira Android companion app (v4.5.15.4), which identifies the paired Mira hormone analyzer by performing only a substring match against the BLE advertisement name, without cryptographic peripheral authentication, a MAC allowlist, or a bonded-identity check. This could allow an attacker to capture live session token information. Users of this healthcare device should stop using the app until the vendor releases a security patch.
Azərbaycanca: Bu zəiflik Mira Android tətbiqində (v4.5.15.4) Mira hormon analizatoru cihazı ilə qoşalaşma zamanı yalnız BLE reklam adının bir hissəsinə əsasən identifikasiya edir; kriptoqrafik autentifikasiya, MAC ünvan icazə siyahısı və ya bağlı cihaz yoxlaması olmadığı üçün təcavüzkar canlı sessiya token məlumatlarını ələ keçirə bilər. Bu, səhiyyə cihazı istifadəçilərinə təsir edir. İstehsalçı təhlükəsizlik yaması təqdim edənə qədər tətbiqin istifadəsi dayandırılmalıdır.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Mira
FAQ2
Why is the BLE pairing vulnerability in the Mira Android app (v4.5.15.4) considered a serious threat?
Because the app identifies the paired Mira hormone analyzer by only performing a substring match against the BLE advertisement name, without cryptographic peripheral authentication, a MAC allowlist, or a bonded-identity check. This allows an attacker to capture live session token information.
What should users do to protect themselves from the CVE-2026-67558 vulnerability until the vendor releases a security patch?
Users should stop using the Mira Android app (v4.5.15.4) until the vendor releases a security patch.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.