Executive brief
A vulnerability exists in the Trusted Computing Group's TPM 2.0 reference implementation, which is core firmware-level security code used to protect cryptographic keys and authentication credentials on computing systems. Google will proactively patch affected systems during standard maintenance windows, and no immediate customer action is required.
Technical details
CVE-2026-6726 (also designated TCGVRT0010) is a vulnerability affecting the Trusted Computing Group's TPM 2.0 reference implementation across all published code revisions. TPM 2.0 is a hardware security module specification responsible for protecting cryptographic keys, secure boot verification, and platform authentication. The exact vulnerability class and attack vector are not disclosed in the advisory, but the firmware-level nature suggests potential memory corruption or cryptographic weakness. Exploitation would require local or adjacent network access to the TPM interface. Google is addressing this via proactive patching during scheduled maintenance windows without requiring customer intervention.
Affected products
- Trusted Computing Group TPM 2.0 Reference Implementation v1.16, v1.38, v1.59, v1.83, v1.84
Timeline
- 2026-08-11: disclosed