SMARTPHONES

Every COROS watch has a major vulnerability exposing your private data

What you need to know

  • A report from SySS GmbH, a German IT brand, indicates that the COROS PACE 3 has “several significant vulnerabilities allowing an unauthenticated attacker within the Bluetooth range” to access your data.
  • The PACE 3 and other COROS watches can be forced-paired to another phone using a legacy Bluetooth “Just works” connection.
  • With access, the hijacker can see your data, reset or reconfigure your device, read your phone notifications, or even send you fake messages.
  • COROS’s CEO has acknowledged this is a “system-level issue” and that they intend to begin addressing them before the end of July.

COROS watches are a popular alternative to fitness brands like Garmin, with affordable pricing and long battery life. But an IT exposé from SySS GmbH has revealed a major security vulnerability, and COROS has been slow to acknowledge and address it.

According to the report, the COROS PACE 3 does not properly authenticate or encrypt the Bluetooth connection between your watch and phone, bypassing the “Secure Connections” tool introduced in Bluetooth 4.2 for a simpler connection.


Source link

Related Articles

Back to top button