CVE-2025-27839: Tangem SDK
Low severity, CVSS 3.2. EPSS: 0.4% chance of exploitation in the next 30 days.
operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuineness check) that causes verification results to be disregarded during the first scan of a card. Exploitation may not have been possible.
Affected products
- Tangem SDK: before 5.18.3 (fixed in 5.18.3)
Published 2025-03-08. Last modified 2026-06-17.