Alivecor develops portable cardiac-monitoring devices and mobile applications for personal electrocardiogram capture and analysis, with its vulnerability footprint concentrated across the Kardia product line and associated firmware. The observed weakness classes center on authentication and encryption handling, including authentication bypass through assumed-immutable data, cleartext transmission of sensitive health information, and missing encryption of stored cardiac data—exposures that reflect the challenge of securing patient-sensitive medical devices. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alivecor over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41627HIGH
The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encryption for its data-over-sound protocols. Exploiting this vu | Oct 27, 2022 | 7.6 | 24 | NO | NO |
CVE-2022-40703MEDIUM CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior
on Android allows an unauthenticated attacker with physical acce | Oct 26, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alivecor.
Media articles that mention a CVE ID that affects a product developed by Alivecor — matched by CVE ID, not by vendor name.