Executive brief
A security vulnerability exists in certain hardware security chips (TPMs) used to protect sensitive cryptographic keys on computers. An attacker with physical access to the device could potentially use specialized equipment to monitor the chip's activity and steal private encryption keys. This could allow an unauthorized person to decrypt sensitive data or impersonate the device, though the attack is difficult to perform and requires high-level access.
Technical details
A side-channel vulnerability (CWE-1300) exists in TPM hardware during the processing of Elliptic Curve Diffie-Hellman (ECDH) operations. The flaw allows an attacker with physical access to the hardware to monitor physical emissions (such as electromagnetic leaks or power consumption) to reconstruct private keys. Exploitation requires high privileges, physical proximity, and high technical complexity to bypass existing protections. Successful exploitation results in a loss of confidentiality for the stored ECDH keys, potentially compromising encrypted communications or identity secrets protected by the TPM.
Affected products
- Generic Trusted Platform Module (TPM)
Timeline
- 2026-05-14: disclosed: Initial disclosure by Israel National Cyber Directorate
- 2026-05-14: advisory: NVD publication date