CVE-2026-66832

Summary

When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context.

Affected Software

VendorProductVersion RangeStatus
Quanovate Tech Inc. (operating as Mira / Mira Care)Mira Firmware1.7.1.47affected
Quanovate Tech Inc. (operating as Mira / Mira Care)Mira Firmware01.07.01.53unaffected
Quanovate Tech Inc. (operating as Mira / Mira Care)Mira Android App4.5.15.4affected
Quanovate Tech Inc. (operating as Mira / Mira Care)Mira Android App4.5.18unaffected

Weaknesses

  • CWE-598: CWE-598 Use of GET request method with sensitive query strings

References