CWE-1300Base

Improper Protection of Physical Side Channels

Stable in the CWE catalog · 34 CVEs mapped

34
CVEs mapped
5.3
Median CVSS
What it is

The device does not contain sufficient protection

mechanisms to prevent physical side channels from exposing

sensitive information due to patterns in physically observable

phenomena such as variations in power consumption,

electromagnetic emissions (EME), or acoustic emissions.

Recent examples
4.3cvss
CVE-2026-18019

CVE-2026-18019 - MEDIUM Severity Vulnerability

Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

MEDIUMno explanation yet
0%
epss
5.3cvss
CVE-2026-17978

CVE-2026-17978 - MEDIUM Severity Vulnerability

Side-channel information leakage in WebCodecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

MEDIUMno explanation yet
0%
epss
4.3cvss
CVE-2026-17942

CVE-2026-17942 - MEDIUM Severity Vulnerability

Side-channel information leakage in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1300
Abstraction
Base
Structure
Simple
Status
Stable
References (21)
https://www.rambus.com/wp-content/uploads/2015/08/DPATechInfo.pdfhttps://link.springer.com/content/pdf/10.1007/3-540-36400-5_4.pdfhttps://www.iacr.org/archive/crypto2014/86160149/86160149.pdfhttps://media.blackhat.com/eu-13/briefings/OFlynn/bh-eu-13-for-cheapstakes-oflynn-wp.pdfhttps://www.usenix.org/legacy/events/sec01/full_papers/gutmann/gutmann.pdfhttps://www.intego.com/mac-security-blog/iphone-pin-pass-code/https://web.archive.org/web/20210107182441/https://ninjalab.io/wp-content/uploads/2021/01/a_side_journey_to_titan.pdfhttps://csrc.nist.gov/csrc/media/events/non-invasive-attack-testing-workshop/documents/08_goodwill.pdfhttps://www.iso.org/standard/60612.htmlhttps://www.rambus.com/wp-content/uploads/2015/08/TVLA-DTR-with-AES.pdfhttps://www.esat.kuleuven.be/cosic/publications/article-3204.pdfhttps://dl.acm.org/doi/pdf/10.5555/3199700.3199717https://eprint.iacr.org/2021/530.pdfhttps://link.springer.com/book/10.1007/978-0-387-38162-6https://informatik.rub.de/veroeffentlichungenbkp/seceng/veroeffentlichungen/2013/pdfs/2013_Side_Channel_Attacks_on_the_Yubikey_2_One-Time_Password_Generator.pdfhttps://eprint.iacr.org/2017/138.pdfhttps://eprint.iacr.org/2019/1013.pdfhttps://www.ti.com/lit/an/swra739/swra739.pdf?ts=1644234570420https://eprint.iacr.org/2022/328.pdfhttps://github.com/HACK-EVENT/hackatdac21/blob/b9ecdf6068445d76d6bee692d163fededf7a9d9b/piton/design/chip/tile/ariane/src/rsa/mod_exp.v#L46:L47https://github.com/HACK-EVENT/hackatdac21/blob/37e42f724c14b8e4cc8f6e13462c12a492778219/piton/design/chip/tile/ariane/src/rsa/mod_exp.v#L47:L51