WHOOP
- Known vulnerabilities
- 0
- Still open
- 0
- KEV open
- 0
- Max CVSS (historical)
- —
Cumulative exposure
Low
Aggregates open CVEs (40%) + KEV (30%) + critical shared permissions (15%) + trackers (10%) + OS EOL (5%). Higher score = more exposed.
-
Open CVEs +0/+50
0 open CVEs, max CVSS 0.0, EPSS 0%
-
Active KEVs +0/+35
0 CISA KEVs still open
-
Permissions +0/+10
0 critical shared permission(s)
-
Trackers +0/+8
0 identification/profiling tracker(s)
-
EOL OS +0/+5
Installed OS is end-of-life
Based on permissions only: no CVE data referenced for this app.
Known vulnerabilities (CVE)
No CVE is currently referenced in NVD for this app on its platform.
The absence of CVEs is not a security guarantee — it can also mean nobody has audited or published findings.
Context
Context
Description
WHOOP is the leading wearable that turns comprehensive health insights into daily action. By capturing dozens of data points every second, WHOOP delivers personalized Sleep, Strain, Recovery, Stress, and health insights—24/7. WHOOP uses those insights to provide coaching based on your body’s unique physiology and recommends everything from when to go to bed to new daily behaviors that will help you reach your goals. If you’re new to WHOOP, you can try both the wearable and app free for 1 month. Terms and conditions apply. WHOOP is screenless, so all your data lives in the WHOOP app—for a distraction-free focus on your health. The WHOOP app requires a WHOOP wearable. How it works: Healthspan*: A powerful way to quantify your age and slow your Pace of Aging. Backed by leading longevity research, it pinpoints the daily habits that impact your long-term health. Sleep: WHOOP helps you understand how well you sleep each night by measuring your Sleep Performance. Every morning, WHOOP provides a Sleep score from 0 to 100%. Sleep Planner calculates how much sleep you need to recover, tailored to your habits, schedule, and goals.
Data collected and shared
Source: App Store · App Privacy · 8 data item(s) declared
Indicative classification based on data sensitivity. "Shared" = transmitted to third parties (publisher-declared).
FAQ
FAQ: WHOOP
Why are no CVEs listed for WHOOP?
No CVE is currently referenced in NVD for WHOOP (com.whoop.iphone) with a iOS CPE configuration. Either none has been publicly disclosed, or none has been mapped yet. Absence of a CVE is not a security guarantee.
What is the latest known version of WHOOP?
The most recent version of WHOOP (com.whoop.iphone) tracked by Appaloosa Scout is 5.65.1, published by Whoop Incorporated.