Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/tink-crypto/tink-java/issues/75 |
|
Wed, 22 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig information as a side channel in order to get information how many bytes of a given tag match the correct tag. This in turn could allow to find a correct tag bytewise. | |
| Title | Observable Timing Discrepancy in Tink-Java and Tink-Android ChunkedMacVerification | |
| Weaknesses | CWE-208 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2026-07-22T18:27:24.251Z
Reserved: 2026-07-10T17:38:15.752Z
Link: CVE-2026-15432
Updated: 2026-07-22T18:13:38.733Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T03:30:04Z