CVE-2026-77974: Softish C6 Ear Camera and EarVision Android Application Missing authentication for critical function
Published Sep 9, 2026
·Updated
After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.
Affected Software
2 affected components
Softish C6 Ear Camera
Android Application
Event History
Sep 9, 2026
CVE Published
via MITRE·03:41 PM
Data Sourced
via MITRE·03:41 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker must spoof the device and obtain one user confirmation. No attacker privileges are required, but user interaction is required.
2
What could a successful attacker do?
A successful attacker may cause the Android application to transmit firmware through an unauthenticated, unsigned update channel. The reported impact includes high confidentiality, integrity, and availability impact.
3
Are all users exposed by default?
The available information does not state whether the affected update behavior is enabled or reachable in the default configuration.