Description
A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-09
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Local Code Execution via Buffer Overflow
Action: Patch
AI Analysis

Impact

A buffer overflow exists in an unknown function of the Apple Notification Center Service Event Handler in the Behavioral Technology Group Pavlok Behavioral Conditioning Wearable firmware up to 20260707. The overflow can allow an attacker to inject or overwrite data on the stack, which could lead to arbitrary code execution or privilege escalation on the device. The vulnerability is associated with common off-by-one and buffer overflow weaknesses (CWE-119, CWE-120).

Affected Systems

Vendors affected: Behavioral Technology Group. Product: Pavlok Behavioral Conditioning Wearable. Firmware versions up to and including 20260707 contain the flaw. All devices running these firmware releases are potentially vulnerable until a patch or update is applied.

Risk and Exploitability

The flaw carries a CVSS score of 9.4, indicating critical severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Attackers must be on the same local network as the device, but once on the network they can exploit the buffer overflow to gain local execution on the wearable. Given the high CVSS and the requirement for local network access, the risk to devices remains high until patched.

Generated by OpenCVE AI on September 10, 2026 at 01:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Pavlok wearable firmware to a release newer than 20260707.
  • Disable or restrict the Apple Notification Center Service if the device firmware allows configuration.
  • Limit local network access to the wearer’s device by segmenting the network or using VLANs, and enforce strong authentication for any services that can reach the wearable.

Generated by OpenCVE AI on September 10, 2026 at 01:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
References

Thu, 10 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
References

Thu, 10 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.
Title Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow
First Time appeared Behavioral Technology Group
Behavioral Technology Group pavlok Behavioral Conditioning Wearable
Weaknesses CWE-119
CWE-120
CPEs cpe:2.3:a:behavioral_technology_group:pavlok_behavioral_conditioning_wearable:*:*:*:*:*:*:*:*
Vendors & Products Behavioral Technology Group
Behavioral Technology Group pavlok Behavioral Conditioning Wearable
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:A/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.6, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Behavioral Technology Group Pavlok Behavioral Conditioning Wearable
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T21:46:47.049Z

Reserved: 2026-09-09T16:16:09.642Z

Link: CVE-2026-87931

cve-icon Vulnrichment

Updated: 2026-09-10T13:38:37.111Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T00:17:24.737

Modified: 2026-09-10T14:39:13.757

Link: CVE-2026-87931

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T12:00:10Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')