Description
A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-09
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow exists in an unknown function of the Apple Notification Center Service Event Handler in the Behavioral Technology Group Pavlok Behavioral Conditioning Wearable firmware up to 20260707. The overflow can allow an attacker to inject or overwrite data on the stack, which could lead to arbitrary code execution or privilege escalation on the device. The vulnerability is associated with common off-by-one and buffer overflow weaknesses (CWE-119, CWE-120).

Affected Systems

Vendors affected: Behavioral Technology Group. Product: Pavlok Behavioral Conditioning Wearable. Firmware versions up to and including 20260707 contain the flaw. All devices running these firmware releases are potentially vulnerable until a patch or update is applied.

Risk and Exploitability

The flaw carries a CVSS score of 9.4, indicating critical severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Attackers must be on the same local network as the device, but once on the network they can exploit the buffer overflow to gain local execution on the wearable. Given the high CVSS and the requirement for local network access, the risk to devices remains high until patched.

Generated by OpenCVE AI on September 10, 2026 at 01:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Pavlok wearable firmware to a release newer than 20260707.
  • Disable or restrict the Apple Notification Center Service if the device firmware allows configuration.
  • Limit local network access to the wearer’s device by segmenting the network or using VLANs, and enforce strong authentication for any services that can reach the wearable.

Generated by OpenCVE AI on September 10, 2026 at 01:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.
Title Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow
First Time appeared Behavioral Technology Group
Behavioral Technology Group pavlok Behavioral Conditioning Wearable
Weaknesses CWE-119
CWE-120
CPEs cpe:2.3:a:behavioral_technology_group:pavlok_behavioral_conditioning_wearable:*:*:*:*:*:*:*:*
Vendors & Products Behavioral Technology Group
Behavioral Technology Group pavlok Behavioral Conditioning Wearable
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:A/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.6, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Behavioral Technology Group Pavlok Behavioral Conditioning Wearable
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-09T23:45:09.054Z

Reserved: 2026-09-09T16:16:09.642Z

Link: CVE-2026-87931

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T00:17:24.737

Modified: 2026-09-10T00:17:24.737

Link: CVE-2026-87931

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T01:45:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')