Impact
A buffer overflow exists in an unknown function of the Apple Notification Center Service Event Handler in the Behavioral Technology Group Pavlok Behavioral Conditioning Wearable firmware up to 20260707. The overflow can allow an attacker to inject or overwrite data on the stack, which could lead to arbitrary code execution or privilege escalation on the device. The vulnerability is associated with common off-by-one and buffer overflow weaknesses (CWE-119, CWE-120).
Affected Systems
Vendors affected: Behavioral Technology Group. Product: Pavlok Behavioral Conditioning Wearable. Firmware versions up to and including 20260707 contain the flaw. All devices running these firmware releases are potentially vulnerable until a patch or update is applied.
Risk and Exploitability
The flaw carries a CVSS score of 9.4, indicating critical severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Attackers must be on the same local network as the device, but once on the network they can exploit the buffer overflow to gain local execution on the wearable. Given the high CVSS and the requirement for local network access, the risk to devices remains high until patched.
OpenCVE Enrichment