ZeroHour

CVE-2026-87931

niche

Buffer overflow in Pavlok Behavioral Conditioning Wearable notification handler

CVSS 4.0
8.6 high
EPSS
<1%p38
Published
()
Modified
AI analysis

CVE-2026-87931 is a buffer overflow (CWE-119/CWE-120) in the Apple Notification Center Service Event Handler of the Behavioral Technology Group Pavlok Behavioral Conditioning Wearable, affecting versions up to and including 20260707. An attacker positioned on the local network (adjacent access, per CVSS 4.0) can send manipulated input to this event-handling component with no privileges and no user interaction required, triggering the overflow. The CVSS 4.0 vector assigns high impact to confidentiality, integrity and availability, and high subsequent-system impacts, indicating a successful attack could crash the wearable or compromise it beyond the device itself. Users of the Pavlok wearable are affected, particularly those using its Apple notification-sync feature, which pairs the device with iPhones. As of this disclosure there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and the vendor was contacted early but did not respond, so no patch is yet known.

What to do: No vendor patch is known as of this disclosure, so monitor Behavioral Technology Group's official channels for a firmware or companion-app update and install it when released. Since exploitation requires adjacent/local-network access, disconnect the wearable from its Bluetooth pairing or turn off its Apple notification-sync feature when not in use to reduce exposure. If you rely on the Pavlok with an iPhone, prioritize applying the vendor's fix promptly once an advisory appears.

Affected
Behavioral Technology Group Pavlok Behavioral Conditioning Wearablethrough 20260707
Estimated exposure
nichelikely at most tens of thousands of devices (niche consumer wearable; no public install-base or scan data) — Pavlok is a small consumer habit-training wristband rather than a mass-market product, and with no vendor install counts or public scan data available, the installed base is assumed to be small, on the order of tens of thousands of devices…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.

Weakness
CWE-119, CWE-120
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.