An issue was discovered in COROS PACE 3 through 3.0808.0. Due to an out-of-bounds read vulnerability, sending a crafted BLE message forces the device to reboot.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://syss.de | third party advisory |
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-028.txt | exploit third party advisory |