The FeliCa vulnerability that caused a stir a year ago is finally disclosed by JVN; severity rated “high”

TL;DR AI
2 min readKey summary
JVN, run by IPA and JPCERT/CC, disclosed a high-severity vulnerability in some Sony FeliCa chips.
The issue affects certain chips shipped before 2017 and could allow data reading or tampering if an attacker has physical access.
Because FeliCa is widely used in payment and transit cards, operators may need to strengthen theft and skimming countermeasures.
The flaw is tracked as CVE-2026-59776, and related parties are being urged to respond.
