Fourth Frontier Frontier X/X2 wearable health monitors contain unauthenticated Bluetooth…
Fourth Frontier Frontier X/X2 wearable health monitors contain unauthenticated Bluetooth LE vulnerabilities allowing attackers to manipulate device functions and inject false health telemetry.
CISA disclosed a critical vulnerability (CVE-2026-5768) affecting Fourth Frontier's Frontier X and X2 wearable cardiac monitoring devices and their companion mobile applications. The devices allow unauthenticated Bluetooth Low Energy (BLE) read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. Attackers within BLE range can perform unauthorized control of device functions including starting or stopping activities, triggering vibrations, causing denial-of-service conditions, and fuzzing characteristic values to induce unexpected behavior.
The companion mobile applications (Android versions below 15.0.0 and iOS versions below 25.0.0) lack proper BLE device authentication, enabling attackers to impersonate legitimate Frontier X2 devices. By cloning BLE advertisements and exposing expected GATT characteristics, attackers can inject fabricated health telemetry including breathing rate, heart rate, strain, and other physiological data into the application. This manipulation of clinical readings could result in device takeover and potential patient harm.
Fourth Frontier is developing a fix but has not yet released remediated firmware or application versions. The vendor recommends users connect their devices through the official app before starting activities, leveraging the single-connection limitation as a temporary mitigation. CISA notes no known public exploitation has been reported, though the vulnerability is exploitable by attackers within Bluetooth range of affected devices.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-148-01
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free