CVE-2026-89034
—Unauthenticated Bluetooth LE Access in TCH QRing R20 Smart Ring
The TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 exposes a Nordic UART Service over Bluetooth Low Energy that enforces no client authentication or command authorization (CWE-306, missing authentication for critical function). Any attacker within BLE range can connect directly to the ring without pairing, authentication, or user approval, bypassing the official companion app and cloud authentication entirely. Once connected, the attacker can read the battery level, activate live heart rate monitoring, and retrieve stored historical heart rate and blood oxygen records, yielding a high confidentiality/privacy impact with no integrity or availability impact. All wearers of this model on the affected firmware are exposed whenever the ring is powered and within Bluetooth range; there is no known public proof-of-concept, no CISA KEV listing, and no confirmed exploitation.
What to do: Check the firmware version in the companion app and apply a patched firmware from TCH when one becomes available (no fixed version was identified in this disclosure). Until then, power the ring off when not in use and be aware that any Bluetooth device within roughly 10 meters can silently read its health data without consent. This is a local, proximity-based privacy exposure, so remote detection and network-level mitigations do not apply.
| TCH QRing smart ring R20_B006 | firmware RT09R20_1.00.00_250318 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, or user approval by exploiting the exposed Nordic UART Service which enforces no client authentication or command authorization. Attackers within Bluetooth Low Energy range can connect directly to the ring, bypassing the official application and cloud authentication, to read battery levels, activate live heart rate monitoring, and retrieve stored historical heart rate and blood oxygen records.
- Weakness
- CWE-306
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.