VYPR

Mira Android companion app

by Mira

CVEs (2)

  • CVE-2026-67558HigAug 11, 2026
    risk 0.48cvss 7.4epss 0.00

    The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live…

  • CVE-2026-66832MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to…