Vulnerabilities in Arm Mbed Crypto and Mbed TLS Expose Private Keys
First seen 18 Feb 2026, 10:13 UTC
•
•43
Export
Article Content
Browse articles
Two vulnerabilities have been identified in Arm Mbed Crypto and Mbed TLS that could allow local attackers to recover private keys through side-channel attacks. CVE-2019-18222, published on January 23, 2020, involves an issue with the ECDSA signature implementation, while CVE-2019-16910, published on September 26, 2019, relates to insufficient entropy in RNG when deterministic ECDSA is enabled.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2019-09-26
CVE-2019-16910 published
2020-01-23
CVE-2019-18222 published
2026-02-18
Information published about both vulnerabilities
More articles in this cluster
Continue Reading
Google Addresses Unreported Chrome Zero-Day Vulnerability
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
Apple Fixes Zero-Day Vulnerability in Software Update
Cisco Fixes Critical AsyncOS Vulnerability Under Attack
CISA Directs Agencies to Address Gogs RCE Vulnerability Exploited in Zero-Day Attacks
Cisco Addresses AsyncOS Zero-Day Exploited by Threat Actors