VYPR
Medium severity5.1NVD Advisory· Published Nov 11, 2025· Updated Apr 15, 2026

CVE-2025-31719

CVE-2025-31719

Description

In TEE EcDSA algorithm, there is a possible memory consistency issue. This could lead to generated incorrect signature results with low probability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper initialization in TEE EcDSA algorithm may cause memory inconsistency, leading to incorrect signature generation with low probability.

The TEE (Trusted Execution Environment) EcDSA algorithm suffers from an improper initialization vulnerability (CWE-665). This memory consistency issue arises during signature generation, causing the algorithm to occasionally produce incorrect signature results. The flaw is inherent to the EcDSA implementation and is classified as a local access vulnerability.

Exploitation requires local access to the device, but does not require any additional privileges or user interaction. An attacker could potentially trigger the condition to generate faulty signatures, though the probability of success is low. The attack surface is limited to devices using the affected chipsets and Android software versions.

If successfully exploited, an attacker could cause denial of service or integrity issues by generating invalid signatures. This could undermine cryptographic operations that rely on correct EcDSA signatures, such as authentication or data integrity checks. The overall CVSS score is 5.1, reflecting medium severity due to low impact on confidentiality but some impact on integrity and availability.

Unisoc has published an advisory [1] detailing affected chipsets and software versions. The vulnerability affects Android versions 13 through 16 on a wide range of chipsets including SC9863A, T610, T760, T820, and others. The recommended mitigation is to apply security updates provided by device OEMs or contact Unisoc for the latest information. No public evidence of active exploitation exists at this time.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.