{"id":61715,"date":"2026-07-21T10:34:10","date_gmt":"2026-07-21T10:34:10","guid":{"rendered":"https:\/\/www.europesays.com\/japan\/61715\/"},"modified":"2026-07-21T10:34:10","modified_gmt":"2026-07-21T10:34:10","slug":"japan-confirms-cryptographic-flaw-in-legacy-sony-felica-cards-no-patch-available","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/japan\/61715\/","title":{"rendered":"Japan Confirms Cryptographic Flaw in Legacy Sony FeliCa Cards, No Patch Available"},"content":{"rendered":"<p>Japan&#8217;s national vulnerability portal formally confirmed today that certain Sony FeliCa contactless IC chips carry a hardware-level cryptographic flaw that enables a proximity-based attack capable of degrading the chip&#8217;s security strength \u2014 and because the defect is baked into the silicon of chips shipped before 2017, no software patch is possible. The <a href=\"https:\/\/jvn.jp\/jp\/JVN40509781\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">JVN advisory JVN#40509781<\/a> assigns the identifier CVE-2026-59776 to the flaw.<\/p>\n<p>Japan Vulnerability Notes (JVN), operated jointly by JPCERT\/CC and the Information-technology Promotion Agency (IPA), published <a href=\"https:\/\/jvn.jp\/jp\/JVN40509781\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">advisory JVN#40509781<\/a> on July 21, 2026. The vulnerability carries a CVSS v4.0 base score of 7.0 (High) and CVSS v3.0 base score of 6.8, with the attack vector classified as Physical \u2014 meaning an adversary must reach close proximity to the card to exploit it.<\/p>\n<p>What Sony FeliCa Is \u2014 and Why Hundreds of Millions of Cards Are in Scope<\/p>\n<p>FeliCa \u2014 short for Felicity Card \u2014 is Sony&#8217;s contactless RFID smart card technology, operating at 13.56 MHz and conforming to the <a href=\"https:\/\/en.wikipedia.org\/wiki\/FeliCa\" rel=\"nofollow noopener\" target=\"_blank\">ISO\/IEC 18092 NFC standard<\/a>. First commercialized with Hong Kong&#8217;s <a href=\"https:\/\/en.wikipedia.org\/wiki\/FeliCa\" rel=\"nofollow noopener\" target=\"_blank\">Octopus transit system<\/a>, FeliCa became the de facto infrastructure for contactless services across Japan and parts of Asia.<\/p>\n<p>By the time Sony launched its 2020-generation chip, <a href=\"https:\/\/www.sony.co.jp\/en\/Products\/felica\/business\/information\/200908.html\" rel=\"nofollow noopener\" target=\"_blank\">more than 1.4 billion FeliCa chips<\/a> had been produced worldwide. The technology spans transit ticketing on rail and bus networks throughout Japan \u2014 <a href=\"https:\/\/en.wikipedia.org\/wiki\/FeliCa\" rel=\"nofollow noopener\" target=\"_blank\">Suica, PASMO, ICOCA<\/a>, and dozens of regional equivalents \u2014 as well as electronic money services at convenience stores, vending machines, and retailers; employee ID and building access cards; university student IDs; and condominium door locks.<\/p>\n<p>The JVN advisory specifically targets chips shipped before 2017. That cutoff corresponds to hardware manufactured in an era before Sony introduced its current-generation chip in 2020, which carries <a href=\"https:\/\/www.sony.co.jp\/en\/Products\/felica\/about\/\" rel=\"nofollow noopener\" target=\"_blank\">ISO\/IEC 15408 EAL6+ certification<\/a> \u2014 among the highest security evaluation levels available for IC systems.<\/p>\n<p>How the Cryptographic Flaw Works<\/p>\n<p>The vulnerability is classified as <a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/325.html\" rel=\"nofollow noopener\" target=\"_blank\">CWE-325 Missing Cryptographic Step<\/a> \u2014 a category that MITRE describes as occurring when a product omits a required operation in a cryptographic algorithm, producing weaker security than the algorithm is advertised to deliver. According to the JVN advisory, an attacker with physical access to an affected card can perform <a href=\"https:\/\/jvn.jp\/jp\/JVN40509781\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">specific operations during the cryptographic exchange process<\/a> that degrade the chip&#8217;s intended security strength, after which reading or tampering with data stored on the card becomes feasible.<\/p>\n<p>The MITRE documentation for <a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/325.html\" rel=\"nofollow noopener\" target=\"_blank\">CWE-325 specifically identifies resource-constrained hardware<\/a> \u2014 devices with limited memory or slower CPUs \u2014 as a common setting for this class of weakness, because designers sometimes omit computationally intensive steps under the mistaken belief they are unnecessary. IC card chips, which derive all power from the reader during the brief communication window and complete a full transaction in <a href=\"https:\/\/www.sony.co.jp\/en\/Products\/felica\/about\/\" rel=\"nofollow noopener\" target=\"_blank\">approximately 0.1 seconds<\/a>, represent exactly this constraint profile.<\/p>\n<p>FeliCa cards communicate contactlessly at a range of <a href=\"https:\/\/en.wikipedia.org\/wiki\/FeliCa\" rel=\"nofollow noopener\" target=\"_blank\">10 centimeters or less<\/a>, which means a reader held at short range \u2014 near a transit gate, in a shared workspace, or in a crowded commute environment \u2014 can initiate the card exchange sequence. The cryptographic degradation that CWE-325 enables does not happen in a single swipe; an attacker would need to engage the card&#8217;s authentication process with specifically crafted operations during that session. But the CVSS Physical attack vector classification reflects the practical reality that &#8220;physical access&#8221; to a contactless card is meaningfully easier than physical access to a device with a port \u2014 a card in a wallet in a bag presents a very different surface than a locked laptop.<\/p>\n<p><a href=\"https:\/\/www.sony.co.jp\/en\/Products\/felica\/business\/information\/2025001.html\" rel=\"nofollow noopener\" target=\"_blank\">Sony confirmed the vulnerability<\/a> and stated that the security of FeliCa-based services rests not only on the chip itself but on the overall system architecture that each service operator builds around it. The company issued <a href=\"https:\/\/www.sony.co.jp\/en\/Products\/felica\/business\/tech-support\/\" rel=\"nofollow noopener\" target=\"_blank\">countermeasure guidelines to service operators<\/a> and directed them to its technical documentation portal for impact assessment and remediation.<\/p>\n<p>Why Hardware Has No Patch \u2014 and What That Means for Users<\/p>\n<p>Unlike software vulnerabilities, which vendors can address by pushing an update, the <a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/325.html\" rel=\"nofollow noopener\" target=\"_blank\">CWE-325 flaw<\/a> in pre-2017 FeliCa chips cannot be fixed by any update Sony or a carrier delivers. The cryptographic step is missing from the chip&#8217;s silicon \u2014 it is a design artifact of the manufacturing era, not a configurable parameter.<\/p>\n<p>For consumers, the practical mitigation guidance in the <a href=\"https:\/\/jvn.jp\/jp\/JVN40509781\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">JVN advisory<\/a> is direct: manage IC cards carefully to prevent theft or skimming. That means keeping cards in RFID-blocking wallets or card sleeves, monitoring e-money and transit accounts for unexpected transactions, and reporting lost or stolen cards immediately.<\/p>\n<p>For service operators \u2014 transit authorities, building managers, employers, universities \u2014 the <a href=\"https:\/\/jvn.jp\/jp\/JVN40509781\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">JVN advisory directs compliance<\/a> with Sony&#8217;s countermeasure guidelines and the FeliCa developer website&#8217;s technical documentation. The principal remediation tools available are: service-level authentication and anomaly detection (catching suspicious card activity before it causes harm), blocklisting of specific cards suspected of compromise, and acceleration of hardware replacement cycles to retire pre-2017 cards from active use.<\/p>\n<p><a href=\"https:\/\/www.jreast.co.jp\/suica\/important-info\/20250828_felica.pdf\" rel=\"nofollow noopener\" target=\"_blank\">JR East for Suica<\/a> stated that its system&#8217;s broader security measures ensure continued safe use. <a href=\"https:\/\/www.jr-odekake.net\/icoca\/applepay\/info\/detail\/2026\/0721.html\" rel=\"nofollow noopener\" target=\"_blank\">ICOCA, operated by JR West<\/a>, confirmed it had been strengthening monitoring since receiving Sony&#8217;s August 2025 report and will continue coordinating with Sony and related operators. Operators of transit and payment networks typically follow replacement cycles measured in years; transit gate infrastructure in Japan operates on <a href=\"https:\/\/atadistance.net\/2025\/08\/29\/kyodo-exclusive-report-claims-some-felica-chips-are-vulnerable\/\" rel=\"nofollow noopener\" target=\"_blank\">five-to-seven-year cycles<\/a>, giving operators an established mechanism to phase out affected cards.<\/p>\n<p>One practical note flagged by Japan transit technology analysts: Mobile FeliCa \u2014 the version embedded in smartphones via the Osaifu-Keitai system, and accessible through Apple Pay and Google Pay in Japan \u2014 is <a href=\"https:\/\/atadistance.net\/2025\/08\/29\/kyodo-exclusive-report-claims-some-felica-chips-are-vulnerable\/\" rel=\"nofollow noopener\" target=\"_blank\">not affected by this vulnerability<\/a>. The flaw is limited to physical IC cards. Travelers and commuters who have moved their Suica or PASMO to Apple Pay or Google Pay are not in scope for this advisory.<\/p>\n<p>A Disclosure Process That Took Nearly a Year \u2014 and What That Reveals<\/p>\n<p>The JVN publication today closes a disclosure process that ran nearly eleven months from its first public exposure \u2014 not because Sony was slow to respond, but because Japan&#8217;s coordinated vulnerability disclosure framework encountered a type of vulnerability it was not designed to handle efficiently.<\/p>\n<p>Under Japan&#8217;s Information Security Early Warning Partnership Guideline, established by METI in 2004, the standard workflow calls for a researcher to report a vulnerability to IPA, JPCERT\/CC to coordinate with the developer, and the developer to prepare a remediation or workaround before public advisory publication \u2014 <a href=\"https:\/\/www.ipa.go.jp\/en\/security\/vulnerabilities\/partnership.html\" rel=\"nofollow noopener\" target=\"_blank\">typically within 45 days of initial contact<\/a>. <a href=\"https:\/\/jvn.jp\/jp\/JVN40509781\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">Yudai Kirishiki of Unknown Technologies<\/a>, Inc. followed this process when he reported the flaw to IPA in late July 2025.<\/p>\n<p>That process was disrupted on August 28, 2025, when Kyodo News published an unauthorized exclusive based on information obtained from sources involved in the disclosure \u2014 before Sony had prepared countermeasures or notified all affected service operators. Sony was forced to issue an emergency statement acknowledging the flaw&#8217;s existence without being able to provide the guidance that gives public disclosure its safety value \u2014 a situation <a href=\"https:\/\/www.watch.impress.co.jp\/docs\/topic\/2045264.html\" rel=\"nofollow noopener\" target=\"_blank\">security expert Hiroshi Tokumaru<\/a> described as increasing user anxiety without enhancing safety. <a href=\"https:\/\/internet.watch.impress.co.jp\/docs\/news\/2045974.html\" rel=\"nofollow noopener\" target=\"_blank\">METI and IPA issued a joint notice<\/a> in September 2025 urging media and researchers to follow established disclosure protocols.<\/p>\n<p>The reason the formal JVN publication arrived eleven months after Kyodo&#8217;s leak \u2014 rather than 45 days after Kirishiki&#8217;s IPA report \u2014 is not documented in any single source but is visible in the structure of the problem. A software vulnerability can be patched; the developer issues an update, distributes it, and the advisory goes out once the patch is available. A hardware vulnerability with no patch instead requires every affected service operator to individually assess impact, strengthen monitoring, issue guidance to their own users, and prepare blocklisting and replacement workflows \u2014 across potentially dozens of transit authorities, payment processors, building managers, and government ID system operators simultaneously. None of Japan&#8217;s standard coordinated disclosure rules were written to govern that multi-party hardware remediation timeline.<\/p>\n<p>That gap \u2014 between a 45-day window designed for software patches and an eleven-month coordination effort required for hardware without patches \u2014 is the structural lesson this disclosure process made visible. It is a gap that will only become more relevant as IoT hardware, embedded systems, and contactless infrastructure continue to age in place.<\/p>\n<p>Current-Generation Chips and the Path Forward<\/p>\n<p>Sony&#8217;s post-2020 FeliCa chips are not affected by CVE-2026-59776. The 2020-generation hardware achieved <a href=\"https:\/\/www.sony.co.jp\/en\/Products\/felica\/business\/information\/200908.html\" rel=\"nofollow noopener\" target=\"_blank\">ISO\/IEC 15408 EAL6+ certification<\/a>, and Sony announced it in 2020 as carrying updated security to address the maturation of attack capabilities. For organizations still operating pre-2017 hardware in building access, employee ID, or IoT deployments, the JVN disclosure is a concrete prompt to prioritize hardware refresh timelines.<\/p>\n<p>The broader significance of the FeliCa disclosure is not specific to Sony or Japan. As RFID and contactless hardware from the 2010s decade continues to operate in transit systems, access control infrastructure, and IoT deployments across Asia and beyond, the computing power required to conduct proximity-based cryptographic attacks has decreased substantially, while the hardware itself cannot be updated. CVE-2026-59776 is a case study in what that combination looks like when it finally reaches formal public disclosure \u2014 and in what coordinated vulnerability disclosure frameworks need to account for when the vulnerability cannot be fixed with a patch.<\/p>\n<p>Frequently Asked QuestionsDoes the Sony FeliCa vulnerability affect my Suica or PASMO transit card \u2014 and do I need a new one?<\/p>\n<p>If you are using a physical Suica, PASMO, ICOCA, or other FeliCa-based transit card that was manufactured before 2017, it is in scope for CVE-2026-59776. All major transit operators \u2014 including JR East for Suica, and JR West for ICOCA \u2014 have stated their service-level security systems (online verification, anomaly detection, and the ability to blocklist individual cards) mean that transit card holders can continue using their cards. That said, if your physical card is old and you have not yet transitioned to Mobile Suica or Mobile PASMO on a smartphone, doing so removes you entirely from the affected hardware class \u2014 Mobile FeliCa is not affected by this flaw.<\/p>\n<p>Can an attacker exploit this flaw without ever touching my card?<\/p>\n<p>The CVSS attack vector for CVE-2026-59776 is classified as Physical (AV:P), meaning the attack requires the attacker to initiate a contactless exchange with your card \u2014 not merely be in the same room. The card communicates at a maximum range of 10 centimeters. In practice, this means an attacker would need to bring a reader to close proximity of your card \u2014 at a transit gate, in a crowded area, or through a bag. RFID-blocking card sleeves or wallets prevent this entirely. No remote or network-based exploitation of this vulnerability is possible.<\/p>\n<p>If there is no patch, what are operators and businesses doing to protect FeliCa-based access systems?<\/p>\n<p>Service operators have received Sony&#8217;s countermeasure guidelines and have been implementing them since late 2025. The countermeasures are system-level: enhanced monitoring of transaction patterns, blocklisting of cards that show signs of compromise, and accelerated replacement cycles for pre-2017 hardware. Operators running building access or employee ID systems on pre-2017 FeliCa cards should consult the Sony FeliCa developer website directly. For organizations with the highest security requirements, the appropriate response is to treat any pre-2017 card as a candidate for replacement rather than monitoring alone.<\/p>\n<p>Why did it take nearly a year between the initial leak and today&#8217;s formal JVN advisory?<\/p>\n<p>Japan&#8217;s coordinated vulnerability disclosure framework is built around a roughly 45-day window for developers to prepare patches before public advisory publication. This flaw has no patch \u2014 it is a hardware design defect in chips that cannot be updated. Instead of a patch, the remediation process required Sony to develop countermeasure guidelines and then coordinate separately with dozens of service operators \u2014 transit authorities, payment processors, building access operators, and government agencies \u2014 each of whom needed to assess impact, strengthen monitoring, and prepare card replacement workflows for their own user populations. That multi-operator coordination for an unpatched hardware vulnerability is exactly the scenario Japan&#8217;s 2004-era disclosure framework was not written to handle, and the eleven-month timeline reflects that structural gap.<\/p>\n","protected":false},"excerpt":{"rendered":"Japan&#8217;s national vulnerability portal formally confirmed today that certain Sony FeliCa contactless IC chips carry a hardware-level cryptographic&hellip;\n","protected":false},"author":2,"featured_media":61716,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[40046,40044,5417,40047,8,40045,33,40048,2042,40043],"class_list":["post-61715","post","type-post","status-publish","format-standard","has-post-thumbnail","category-japan","tag-contactless-card","tag-cve-2026-59776","tag-cybersecurity","tag-hardware-vulnerability","tag-japan","tag-japan-transit-card-security","tag-nihon","tag-rfid","tag-sony","tag-sony-felica-vulnerability"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/japan\/wp-json\/wp\/v2\/posts\/61715","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/japan\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/japan\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/japan\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/japan\/wp-json\/wp\/v2\/comments?post=61715"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/japan\/wp-json\/wp\/v2\/posts\/61715\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/japan\/wp-json\/wp\/v2\/media\/61716"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/japan\/wp-json\/wp\/v2\/media?parent=61715"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/japan\/wp-json\/wp\/v2\/categories?post=61715"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/japan\/wp-json\/wp\/v2\/tags?post=61715"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}