Published:2026/07/21  Last Updated:2026/07/21

JVN#40509781
Vulnerability in certain IC chips of contactless IC card "FeliCa"

Overview

For certain FeliCa IC chips shipped by Sony Corporation in or before 2017, a certain operation during cryptographic processing may compromise the intended security strength.

Products Affected

  • Certain FeliCa IC chips shipped in or before 2017

Description

For certain FeliCa IC chips shipped by Sony Corporation in or before 2017, a certain operation during cryptographic processing may compromise the intended security strength.

  • Missing cryptographic step (CWE-325)
    • CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 7.0
    • CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score 6.8
    • CVE-2026-59776

Impact

If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.

Solution

Apply the Workaround
For service providers:

  • Assess the impact on your services and implement appropriate countermeasures in accordance with the mitigation guidelines provided by the vendor and the technical documentation available on the vendor's website.
For service users:
  • Manage your IC card appropriately to prevent it from being stolen or skimmed.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

KIRISHIKI Yudai of Unknown Technologies Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-59776
JVN iPedia JVNDB-2026-000100