CVE-2026-87726: Low severity NXP NXPNfcRdLib RC663 vulnerability
Insufficient API bounds checking in phalFelica in NXP NXPNfcRdLib RC663 through 07.14.00Pub may allow an attacker with privileges or an untrusted third party to access unintended memory regions, potentially leading to limited loss of confidentiality, integrity, and availability. All software versions from 07.18.00 onwards have fixed this problem.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NXP NXPNfcRdLibto a version that resolves this vulnerability.Fixed in 07.18.00
Event History
Frequently Asked Questions
Which versions need remediation?
NXP NXPNfcRdLib RC663 versions through 07.14.00_Pub are affected. Software versions 07.18.00 and later contain the fix.
What level of access is required to exploit this issue?
Exploitation requires local access, high privileges, and high attack complexity. No user interaction is required.
What is the potential impact?
The bounds-checking flaw can allow access to unintended memory regions, with limited potential impact to confidentiality, integrity, and availability.