Unencrypted BLE Transmission and DoS Flaw Expose Apollo Pharmacy Glucose Monitor Users
The Apollo Pharmacy APG-01 BT blood glucose monitor contains two serious vulnerabilities: one allowing passive interception of sensitive health data over Bluetooth Low Energy (CVE-2026-50034), and another enabling denial-of-service by monopolizing the device's single connection slot (CVE-2026-52866). These flaws are particularly dangerous because they target a medical device that handles protected health information (PHI), meaning real patients could have their glucose readings exposed or be locked out of a life-relevant monitoring tool. The situation is compounded by Apollo Pharmacy's failure to respond to CISA's coordination requests, leaving users with no vendor-issued remediation path. This highlights the broader risk of IoT and connected medical devices entering the market without adequate security validation or post-market vulnerability response processes.
Tactical Insight
Immediate actions
- Disable Bluetooth on the APG-01 BT device when not actively in use to minimize the attack surface for nearby adversaries.
- Avoid using the device in public or high-density areas where malicious actors within BLE range could intercept transmissions.
- Contact Apollo Pharmacy directly and request a security patch or firmware update timeline, escalating to regulatory bodies (e.g., FDA, CISA) if unresponsive.
Long-term improvements
- Require BLE-enabled medical devices to implement authenticated and encrypted communication (e.g., BLE pairing with AES-128) before procurement or deployment.
- Establish a vendor security assessment process that includes mandatory incident response SLAs as a condition of supplier contracts.
- Maintain an inventory of all connected medical devices and track their CVE exposure using a vulnerability management platform.
Detection & monitoring measures
- Deploy BLE monitoring tools in clinical environments to detect unauthorized scanning or connection attempts targeting medical devices.
- Subscribe to CISA ICS-CERT advisories and automate alerting for CVEs affecting devices in your organization's medical device inventory.
- Implement network/RF anomaly detection to identify unusual Bluetooth activity patterns indicative of connection-slot exhaustion (DoS) attacks.