Mira Advisory Exposes Bluetooth Trust Break

CISA published an advisory covering eight CVEs in Mira Hormone Monitor firmware 1.7.1.47 and Mira Android App 4.5.15.4, with flaws that can expose health data, change health information, and let an attacker take over user accounts. The affected products are deployed worldwide in healthcare and public health settings. The key issue is the Bluetooth Low Energy (BLE) link: a nearby attacker can talk to the monitor without authenticating, so the device may accept commands anyway. That can let someone rebind the monitor to an attacker account, read stored hormone measurements, force a reboot into bootloader mode, or pull session tokens, which turns a local radio attack into a trust and records problem, not just an app problem. For clinics and users who rely on the monitor for fertility tracking, the exposure sits across the device and companion app. A normal-looking phone app does not rule out compromise in the monitor’s Bluetooth layer, and the consequences can reach account integrity and health records even without internet-facing exploitation.

Part of the PlainSec briefing for 2026-08-12

Every edition of this story: Mira Advisory Exposes Bluetooth Trust Break

Sources