CVE-2025-27839: Tangem SDK

Low severity, CVSS 3.2. EPSS: 0.4% chance of exploitation in the next 30 days.

operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuineness check) that causes verification results to be disregarded during the first scan of a card. Exploitation may not have been possible.

Affected products

  • Tangem SDK: before 5.18.3 (fixed in 5.18.3)

Published 2025-03-08. Last modified 2026-06-17.