Executive brief
A security flaw exists in certain Sony FeliCa IC chips, which are widely used in contactless smart cards for transit, payments, and access control. If an attacker gains physical access to a card, they may be able to bypass security protections to read or modify the data stored on the chip. This could lead to unauthorized access to services or the tampering of digital balances and identity information.
Technical details
A Missing Cryptographic Step (CWE-325) vulnerability exists in the firmware of certain Sony FeliCa IC chips manufactured and shipped in or before 2017. The flaw occurs during specific cryptographic processing operations, which fails to maintain the intended security strength of the chip's data protection mechanisms. An attacker with physical access to the IC chip can exploit this weakness to perform unauthorized read or write operations on the stored data. While the vulnerability is hardware-based, Sony has issued mitigation guidelines to service providers to enhance system-level security. No software patch is available for the physical chips themselves due to their hardware nature.
Affected products
- Sony Corporation FeliCa IC chips shipped in or before 2017
Timeline
- 2025-08-28: other: Initial internal confirmation by Sony
- 2026-07-21: advisory: Public disclosure via JVN and Sony update
- 2026-07-21: disclosed: CVE-2026-59776 published