ThreatCluster

Vulnerabilities in Arm Mbed Crypto and Mbed TLS Expose Private Keys

First seen 18 Feb 2026, 10:13 UTC Api.Msrc.Microsoft 43

Article Content

Browse articles
ThreatCluster

Two vulnerabilities have been identified in Arm Mbed Crypto and Mbed TLS that could allow local attackers to recover private keys through side-channel attacks. CVE-2019-18222, published on January 23, 2020, involves an issue with the ECDSA signature implementation, while CVE-2019-16910, published on September 26, 2019, relates to insufficient entropy in RNG when deterministic ECDSA is enabled.

Timeline

2019-09-26
CVE-2019-16910 published
2020-01-23
CVE-2019-18222 published
2026-02-18
Information published about both vulnerabilities