Fourth Frontier drew ICSMA-26-148-01 for the Frontier X and Frontier X2 wearable cardiac monitors and their mobile apps. CVE-2026-5768, missing authentication for a critical function, base score 8.8. An attacker reads and writes arbitrary handle values and alters clinical readings, which on an ECG wearable is the whole product. A monitor an attacker can rewrite is a monitor that can lie to a clinician.

Authentication on a critical function is the check that makes a caller prove it is allowed before the device acts. Where that check is missing, the device treats any party able to deliver the request as authorized, and on a wirelessly driven product the population able to deliver a request is everyone within radio range. The handle values in question are the attributes the device exposes over its wireless link, the fields holding its settings and its data.

An electrocardiogram is worth only what a clinician's trust in the trace makes it. A wearable whose readings can be rewritten erodes that trust at the source, because a falsified rhythm can steer care the wrong way, masking a real event or inventing one that never happened. Tampering of this sort leaves a plausible record rather than an obvious gap, which is what makes an integrity flaw on a diagnostic wearable so corrosive.

Proximity is the natural limit on a flaw like this, since the attacker must be near enough for the wireless link to reach, yet in a clinic corridor, a waiting room or a shared home space that distance is undemanding. Once a vendor engages, corrections to this class of defect travel the same coordinated path, a private report, an advisory, and updated software, before the weakness becomes public knowledge.

Fixed in Android 15.0.0 and iOS 25.0.0, though the X2 was listed as all-versions affected. Shakir Zari and Jerin Sunny reported it. Consumer cardiac wearables keep arriving with the security maturity of fitness trackers and the clinical weight of diagnostic devices, and the gap between those two is where these findings live.