Project Subscriptions
No data.
No advisories yet.
Solution
Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.
Workaround
No workaround given by the vendor.
Tue, 11 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context. | |
| Title | Mira Hormone Monitor, Mira Android App Use of GET request method with sensitive query strings | |
| Weaknesses | CWE-598 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-11T20:49:56.584Z
Reserved: 2026-08-03T16:54:56.493Z
Link: CVE-2026-66832
No data.
Status : Received
Published: 2026-08-11T21:17:49.713
Modified: 2026-08-11T21:17:49.713
Link: CVE-2026-66832
No data.
OpenCVE Enrichment
No data.