Apollo glucose monitor exposes patient data via BLE
Two Bluetooth Low Energy vulnerabilities in Apollo Pharmacy's APG-01 BT glucose monitor allow attackers to intercept patient glucose readings and block legitimate connections.
CISA has disclosed two vulnerabilities in Apollo Pharmacy's Blood Glucose Monitoring System (Model APG-01 BT, version 0x0110_v1.1.0) affecting devices deployed in India. CVE-2026-50034 enables attackers within BLE range to passively intercept wireless communications and obtain sensitive health information, including glucose measurement values, due to cleartext transmission. CVE-2026-52866 allows an attacker to monopolize the device's single BLE connection slot through a missing authorization weakness, creating a denial-of-service condition that prevents legitimate users from connecting.
The vulnerabilities require physical proximity to exploit and are not remotely exploitable. Apollo Pharmacy did not respond to CISA's coordination attempts, and no vendor patches are currently available. CISA recommends users contact Apollo Pharmacy directly and follow general Bluetooth security guidance. No public exploitation targeting these specific vulnerabilities has been reported at this time.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-169-01
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free