Fourth Frontier drew ICSMA-26-148-01 for the Frontier X and Frontier X2 wearable cardiac monitors and their mobile apps. CVE-2026-5768, missing authentication for a critical function, base score 8.8. An attacker reads and writes arbitrary handle values and alters clinical readings, which on an ECG wearable is the whole product. A monitor an attacker can rewrite is a monitor that can lie to a clinician.
Fixed in Android 15.0.0 and iOS 25.0.0, though the X2 was listed as all-versions affected. Shakir Zari and Jerin Sunny reported it. Consumer cardiac wearables keep arriving with the security maturity of fitness trackers and the clinical weight of diagnostic devices, and the gap between those two is where these findings live.