As cited
Copy frozen at (site build).
vulnerabilities
Mira Hormone Monitor, Mira Android App
The Mira Hormone Monitor device and Android app contain eight critical vulnerabilities affecting firmware version 1.7.1.47 and app version 4.5.15.4. These flaws enable attackers to access health profiles, hijack accounts, extract sensitive data in cleartext, and cause denial-of-service conditions through authentication bypasses, hardcoded credentials, weak password validation, and improper handling of session tokens. Updates are available: iOS app v3.5.18, Android app v4.5.18, and firmware v01.07.01.53.
Why it matters: Women using Mira for fertility and ovulation tracking face immediate risk of reproductive health data theft, account takeover, and manipulation of their medical records; practitioners supporting users of this device should recommend immediate app and firmware updates and verify completion given the critical CVSS scores (up to 9.8) and multiple remote exploitation paths.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Mira Hormone Monitor, Mira Android App
The Mira Hormone Monitor device and Android app contain eight critical vulnerabilities affecting firmware version 1.7.1.47 and app version 4.5.15.4. These flaws enable attackers to access health profiles, hijack accounts, extract sensitive data in cleartext, and cause denial-of-service conditions through authentication bypasses, hardcoded credentials, weak password validation, and improper handling of session tokens. Updates are available: iOS app v3.5.18, Android app v4.5.18, and firmware v01.07.01.53.
Why it matters: Women using Mira for fertility and ovulation tracking face immediate risk of reproductive health data theft, account takeover, and manipulation of their medical records; practitioners supporting users of this device should recommend immediate app and firmware updates and verify completion given the critical CVSS scores (up to 9.8) and multiple remote exploitation paths.
- Source published
- First seen by Cybersecurity Tracker