An issue was discovered in COROS PACE 3 through 3.0808.0. Due to an out-of-bounds read vulnerability, sending a crafted BLE message forces the device to reboot.
An attacker within Bluetooth Low Energy (BLE) range sends a specially crafted BLE message to the device. The device firmware performs a data read outside the boundaries of the allocated memory buffer (out-of-bounds read), which leads to system instability and forces the smartwatch to reboot. The attack does not require prior authentication or user interaction.
An attacker can remotely restart the device multiple times, causing persistent unavailability of smartwatch functions (denial of service, DoS). Additionally, reading data outside the buffer may potentially expose fragments of the device memory contents.
Apply patches available from the manufacturer according to the references. Detailed information regarding the fixed firmware version is available in the SySS advisory: https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-028.txt
Yftech COROS PACE 3 smartwatch with firmware version 3.0808.0 and earlier
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HYftech Coros Pace 3
HWYftechall versionsYftech Coros Pace 3 Firmware
OSYftech≤ 3.0808.0
Related vulnerabilities
Brak uwierzytelnienia BLE w COROS PACE 3 — atak machine-in-the-middle
Brak walidacji certyfikatu TLS w COROS PACE 3 — atak MITM
COROS PACE 3 — pobieranie firmware przez niezaszyfrowane HTTP (MitM)
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connec...
An issue was discovered in COROS PACE 3 through 3.0808.0. Due to a NULL pointer dereference vulnerability, sen...