CVE-2026-15432
Vulnerability Description
When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig information as a side channel in order to get information how many bytes of a given tag match the correct tag. This in turn could allow to find a correct tag bytewise.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-208
Source
NVD
Vendor
Google
Product
Tink-Java, Tink-Android
Discussion (0)
Add Comment
No comments yet. Be the first!