Join us at hack.lu 2026 — Info & Registration
Duration: 30 min
Type: Talk
Speakers: Mohamed Ouad, Bartek Górkiewicz
Abstract
Continuous glucose monitors (CGMs) stream health information over Bluetooth Low Energy from body-worn sensors to smartphones and the vendors’ clouds. Millions of people depend on this communication system every day. However, existing CGM regulations tend to focus on medical-device compliance and operational requirements, while their security posture as connected medical IoT devices is often not fully evaluated.
Over a two-month research effort, we conducted a comparative security assessment of four commercial continuous glucose monitoring (CGM) sensors, covering wireless pairing mechanisms, mobile applications, embedded interfaces, and portions of the supporting cloud infrastructure. Across multiple vendors, we identified recurring architectural weaknesses affecting user device trust, communication security, sensor management functionality, and backend authorization controls.
Guided by a detailed threat model, we analyzed both the design and implementation decisions behind these platforms. In this talk, we will demonstrate how attackers in close proximity can abuse weaknesses in device pairing and trust establishment to impersonate trusted devices, why protocol obscurity at the wireless layer fails as a security boundary, and what manufacturers must change to build secure CGM ecosystems.
Attendees will leave with a clear understanding of the relevant threat scenarios, the technical flaws introduced during the design and manufacturing of these devices, and the broader implications such weaknesses have in today’s always-connected society. The talk will also highlight how insecure wireless connectivity, weak trust assumptions, and poor security engineering practices can directly impact the safety, privacy, and reliability of modern medical ecosystems.
Description
Many modern real-time Continuous Glucose Monitors (CGMs) commonly use Bluetooth Low Energy in the 2.4 GHz ISM band, sharing spectrum with devices such as wireless keyboards and smart lights. However, modern CGMs are not just wireless sensors: they are connected medical IoT platforms composed of a body-worn device, a mobile application, and vendor cloud services. We assessed four CGM ecosystems using an end-to-end threat model that evaluates the wireless link, the body-worn sensor, the Android mobile application, and selected cloud functionalities. The model covers threats to availability, confidentiality, device trust, firmware integrity, local storage, mobile-app exposure, privacy controls, and backend authorization.
For each threat, we validated both the design and implementation of the target CGM platforms. We reviewed:
- Bluetooth Low Energy: pairing and re-pairing behavior, GATT services, proprietary handshakes, replay resistance, glucose measurement flows, control characteristics, sniffing exposure, and availability risks such as connection flooding or RF interference
- Mobile applications: Android clients through static and dynamic analysis, including local storage of sensitive data, exported activities, deep links, app-to-device trust assumptions, and obfuscation/packers
- CGM sensors: management protocols, firmware update paths, sensor states, residual glucose data after sensor expiration, physical debug interfaces, onboard memory exposure, and NFC bootstrap or NFC command handling, where applicable
- Cloud backends: authenticated API authorization, object-level access control, account-device-sensor binding, synchronization behavior, and consistency between in-app privacy controls and backend data flows. Cloud testing was limited to researcher-controlled accounts, devices, and sensors
The target platforms were the Sibionics GS3, Sinocare iCan i3, FreeStyle Libre 3, and Dexcom G7.
We assessed four CGM platforms using only accounts, devices, and sensors under our control. Our testing included BLE capture, Android app reversing, pairing replay using our own BLE central, and targeted cloud API analysis.
This is a partial list of the main issues we found:
- Unauthorized pairing and glucose access: using self-built BLE clients, we reproduced the vendors’ GATT flows and completed application-level authentication from our own BLE central without the user’s phone or consent. On affected devices, the proprietary handshakes relied on recoverable cryptographic keys, including RC4/AES-based flows. We then enabled CGM notifications, retrieved live readings and history, and in some cases issued calibration or control writes normally sent by the official app
- Sniffable “encrypted” traffic: with weak BLE pairing and keys recovered from app-native libraries and firmware, we decrypted glucose-related traffic from BLE captures. Application-layer encryption did not hold once secrets from both endpoints were known
- Embedded management from proximity: on some tested sensors, BLE management and firmware-update interfaces were accessible without authentication. Even if firmware images were required to be signed, the exposed update path still raises downgrade risks
- Cloud authorization and privacy: We identified issues in the backend authorization controls that could allow an authenticated test account to access glucose data outside its intended scope. We also observed cases where uploads and pairing-related metadata, including location, reached backend services even when in-app cloud sync was disabled
Whether you are a healthcare technology professional, an IoT security engineer, or simply a user of these devices, this talk will provide a comprehensive overview of the risks associated with connected CGM platforms - especially when security is not considered a core design requirement. Through practical demonstrations and real-world attack scenarios, attendees will gain insight into how seemingly minor implementation flaws can expose sensitive medical data, undermine device integrity, and ultimately impact user safety.
The session will also explore the broader challenges of securing modern wireless medical ecosystems in a world where connectivity and cost are increasingly prioritized over resilience and security-by-design.