PT-2025-26320 · Coros · Coros
Moritz Abrell
·
Published
2025-06-20
·
Updated
2025-06-21
·
CVE-2025-32875
CVSS v3.1
5.7
Medium
| Vector | AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
COROS application versions 3.8.12 and earlier
Description:
The issue concerns the COROS application's handling of Bluetooth pairing and bonding. The application does not initiate or enforce pairing and bonding, and the watch also does not enforce these security measures. As a result, data transmitted via Bluetooth Low Energy (BLE) remains unencrypted, allowing attackers within range to intercept the communication. Even if a user manually initiates pairing and bonding in the Android settings, the application continues to transmit data without requiring the watch to be bonded, enabling attackers to exploit the communication. This could be used to conduct an active machine-in-the-middle attack.
Recommendations:
For versions 3.8.12 and earlier, as a temporary workaround, consider disabling Bluetooth functionality in the COROS application until a patch is available. Restrict access to sensitive data transmitted via BLE to minimize the risk of exploitation. Avoid using the COROS application for sensitive communications until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coros