CVE-2026-87931 CRITICAL

CVE-2026-87931: Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow

Vendor Behavioral Technology Group
Product Pavlok Behavioral Conditioning Wearable
Weakness CWE-120
Published September 9, 2026
Last update September 9, 2026

CVSS base score

9.4/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P

What the vulnerability does

01Description

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.

Key dates

02Disclosure timeline

September 9, 2026 CVE published