CVE-2026-15432: Google Tink Java

Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.

When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig information as a side channel in order to get information how many bytes of a given tag match the correct tag. This in turn could allow to find a correct tag bytewise.

Affected products

  • Google Tink Java: up to and including 1.21.0

Published 2026-07-21. Last modified 2026-09-22.