CVE-2026-15432
When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig information as a side channel in order to get information how many bytes of a given tag match the correct tag. This in turn could allow to find a correct tag bytewise.
Published:Jul 21, 2026
Last Modified:Jul 27, 2026
EPS:Jul 21, 2026
EPSS Score:0.00185
CVSS Score:8.2
Affected Products
Vendor
Product
Action
Vendor
Google
Product
Tink Android
Google
Tink Android
Vendor
Google
Product
Tink Java
Google
Tink Java
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
