Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/tink-crypto/tink-java/issues/75 |
|
Mon, 27 Jul 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google tink Android Google tink Java |
|
| Vendors & Products |
Google
Google tink Android Google tink Java |
Wed, 22 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig information as a side channel in order to get information how many bytes of a given tag match the correct tag. This in turn could allow to find a correct tag bytewise. | |
| Title | Observable Timing Discrepancy in Tink-Java and Tink-Android ChunkedMacVerification | |
| Weaknesses | CWE-208 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2026-07-22T18:27:24.251Z
Reserved: 2026-07-10T17:38:15.752Z
Link: CVE-2026-15432
Updated: 2026-07-22T18:13:38.733Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-27T20:40:32Z