Executive brief
Google Tink, a cryptographic library used to secure data in Java and Android applications, contains a flaw in how it verifies message authentication codes (MACs). An attacker could potentially use timing measurements to guess the secret security tags byte-by-byte. If successful, this would allow an attacker to forge valid security tags, potentially leading to unauthorized data modification or bypassing integrity checks.
Technical details
A timing side-channel vulnerability (CWE-208) exists in the ChunkedMacVerification object within Google Tink-Java and Tink-Android. The implementation performs a non-constant time comparison when verifying the resulting MAC tag against the expected value. This allows a remote attacker to observe timing discrepancies to determine how many bytes of a provided tag match the correct tag, eventually recovering the full tag through a byte-by-byte brute-force approach. The issue affects all versions up to and including 1.21.0 and was addressed in subsequent commits (e.g., 175df91).
Affected products
- Google Tink-Java All releases up to and including 1.21.0
- Google Tink-Android All releases up to and including 1.21.0
Timeline
- 2026-06-08: patched: Fix committed to repository
- 2026-07-02: disclosed: Public issue opened as reference
- 2026-07-21: advisory: NVD publication date