[Japanese]

JVNDB-2026-000100

Vulnerability in certain IC chips of contactless IC card "FeliCa"

Overview

For certain FeliCa IC chips shipped by Sony Corporation in or before 2017, a certain operation during cryptographic processing may compromise the intended security strength.
  • Missing cryptographic step (CWE-325) - CVE-2026-59776
KIRISHIKI Yudai of Unknown Technologies Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 6.8 (Medium) [IPA Score]
  • Attack Vector: physics
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: High
CVSS v4 Severity
Base Metrics: 7.0 (High) [IPA Score]
  • Access Vector (AV): Physical
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): None
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): High
  • Integrity Impact (VI): High
  • Availability Impact (VA): High
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
Affected Products


Sony Corporation
  • Certain FeliCa IC chips shipped in or before 2017

Impact

If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.
Solution

[Apply the Workaround]
For service providers:
  • Assess the impact on your services and implement appropriate countermeasures in accordance with the mitigation guidelines provided by the vendor and the technical documentation available on the vendor's website.
For service users:
  • Manage your IC card appropriately to prevent it from being stolen or skimmed.
Vendor Information

Sony Corporation
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2026-59776
References

  1. JVN : JVN#40509781
Revision History

  • [2026/07/21]
      Web page was published