CVE-2026-33697Disclosure(ultraviolet / cocos_ai)

MEDIUMCVSS 6.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch ultraviolet cocos_ai systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Cocos AI is a confidential computing system for AI. The current implementation of attested TLS (aTLS) in CoCoS is vulnerable to a relay attack affecting all versions from v0.4.0 through v0.8.2. This vulnerability is present in both the AMD SEV-SNP and Intel TDX deployment targets supported by CoCoS. In the affected design, an attacker may be able to extract the ephemeral TLS private key used during the intra-handshake attestation. Because the attestation evidence is bound to the ephemeral key but not to the TLS channel, possession of that key is sufficient to relay or divert the attested TLS session. A client will accept the connection under false assumptions about the endpoint it is communicating with — the attestation report cannot distinguish the genuine attested service from the attacker's relay. This undermines the intended authentication guarantees of attested TLS. A successful attack may allow an attacker to impersonate an attested CoCoS service and access data or operations that the client intended to send only to the genuine attested endpoint. Exploitation requires the attacker to first extract the ephemeral TLS private key, which is possible through physical access to the server hardware, transient execution attacks, or side-channel attacks. Note that the aTLS implementation was fully redesigned in v0.7.0, but the redesign does not address this vulnerability. The relay attack weakness is architectural and affects all releases in the v0.4.0–v0.8.2 range. This vulnerability class was formally analyzed and demonstrated across multiple attested TLS implementations, including CoCoS, by researchers whose findings were disclosed to the IETF TLS Working Group. Formal verification was conducted using ProVerif. As of time of publication, there is no patch available. No complete workaround is available. The following hardening measures reduce but do not eliminate the risk: Keep TEE firmware and microcode up to date to reduce the key-extraction surface; define strict attestation policies that validate all available report fields, including firmware versions, TCB levels, and platform configuration registers; and/or enable mutual aTLS with CA-signed certificates where deployment architecture permits.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-322CWE-346

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cocos_ai

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 15 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • Peaked 1d ago at 4 mentions (2026-08-03); latest day: 1
  • 15 total mentions across 9 days

Affected systems

Products
cocos_ai

Deep dive

Activity timeline15 mentions / 9d
01234Mentions · 2026-03-27: 3Mentions · 2026-07-05: 2Mentions · 2026-07-07: 1Mentions · 2026-07-08: 1Mentions · 2026-07-09: 1Mentions · 2026-07-10: 1Mentions · 2026-07-11: 1Mentions · 2026-08-03: 4Mentions · 2026-08-12: 1PoC Mentioned / Linked · 2026-07-05: 2PoC Mentioned / Linked · 2026-07-08: 1PoC Mentioned / Linked · 2026-08-03: 4Exploit Tool / Code · 2026-08-03: 3Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-08-12: 1Technical Details · 2026-03-27: 2Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-10: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-12: 103-2707-0507-0707-0807-0907-1007-1108-0308-12
Signal classification5 categories
Disclosure
746.7%
PoC
320.0%
Patch
213.3%
General
213.3%
Exploit
16.7%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-03-273
Disclosure2Patch1
2026-07-052
Disclosure1PoC1
2026-07-071
Patch1
2026-07-081
Disclosure1
2026-07-091
Disclosure1
2026-07-101
Disclosure1
2026-07-111
General1
2026-08-034
Exploit1General1PoC2
2026-08-121
Disclosure1
Full discourse15 posts
  • 曾哥@AabyssZG
    Disclosure

    Confidential computing promises trust in untrusted clouds. But what if the attestation protocol itself becomes the weak link? Team @M_UsamaSardar report http://Intra-handshake.fail (CVE-2026-33697), CVSS 7.5, in Attested TLS. Details: https://www.linkedin.com/posts/usama-sardar_confidentialcomputing-cve-cvss-share-7479514977448501248-N2mX/ #CVE #IETF

    Post summary

    Team @M_UsamaSardar reports CVE‑2026‑33697 affecting Attested TLS with a CVSS of 7.5, providing a link for further details.

    100841.8K
    12.3K followersView on X
  • 曾哥@AabyssZG
    PoC

    @M_UsamaSardar Technical materials for readers who want to go deeper: Paper/preprint: https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS Formal model & artifact repo: https://github.com/CCC-Attestation/formal-spec-KBS CVE: https://www.cve.org/CVERecord?id=CVE-2026-33697

    Post summary

    The tweet supplies links to a scholarly preprint and a formal specification repository for CVE‑2026‑33697, suggesting that proof‑of‑concept and detailed technical analysis exist, but no exploit code, patch, or evidence of active exploitation is provided.

    10032675
    12.3K followersView on X
  • suzaki@KuniSuzaki
    General

    Paper http://Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS [ResearchGate26] https://www.researchgate.net/profile/Muhammad-Sardar-6/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS/links/6a42e97d6d8ade5852c062b3/Intra-handshakefail-CVE-2026-33697-High-severity-CVE-in-Attested-TLS.pdf Muhammad Usama Sardar先生のAttested TLSの研究。

    Post summary

    The post references a research paper on CVE‑2026‑33697—a high‑severity issue in Attested TLS—but provides no exploit, patch, or detailed technical information.

    10031254
    2.2K followersView on X
  • Israel@f1tym1
    Disclosure

    TU Dresden researchers disclosed CVE-2026-33697, a fundamental flaw in attested TLS allowing attackers to relay connections. https://ift.tt/q9gSWnx

    Post summary

    TU Dresden researchers disclosed CVE‑2026‑33697, a flaw in attested TLS that lets attackers relay connections, with no indication of active exploitation or available patches.

    1001062
    1.0K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    The high-severity Attested TLS vulnerability CVE-2026-33697 allows attackers to relay traffic and compromise secure cloud environments. #AttestedTLS #CVE202633697 #CloudSecurity #Cryptography #Vulnerability http://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/

    Post summary

    The post announces the high‑severity CVE‑2026‑33697 in Attested TLS, noting it allows traffic relay to compromise cloud environments and provides a link that likely hosts PoC code, without any evidence of active exploitation or patched fixes.

    10010476
    12.5K followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    New Attested TLS flaw (CVE-2026-33697) enables connection diversion, jeopardizing data privacy/integrity in transit (WhatsApp affected). Critical Telegram flaw grants session access. Patch now! (July 6) #Cybersecurity #Anonymous #News

    Post summary

    A newly disclosed TLS vulnerability (CVE-2026-33697) affecting WhatsApp and Telegram has been patched as of July 6, addressing connection diversion and session hijacking risks.

    1001078
    14 followersView on X
  • Muhammad Usama Sardar@M_UsamaSardar
    Disclosure

    Vyacheslav Dubeyko, Jean-Marie Jacquet, and I show that trust in #ConfidentialComputing is broken by discovering a high-severity #CVE-2026-33697 with a #CVSS score of 7.5 out of 10. It is the #most #severe vulnerability in the published literature. https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS

    Post summary

    The authors announce the discovery of CVE‑2026‑33697, a high‑severity vulnerability in Confidential Computing with a CVSS score of 7.5, and provide a link to their detailed research publication.

    0001059
    16 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33697 Cocos AI is a confidential computing system for AI. The current implementation of attested TLS (aTLS) in CoCoS is vulnerable to a relay attack affecting all versions … https://www.cve.org/CVERecord?id=CVE-2026-33697

    Post summary

    The post announces CVE-2026‑33697, noting that CoCoS’s attested TLS implementation is vulnerable to a relay attack across all versions.

    00010162
    56.9K followersView on X
  • Imran Siddique@mosiddi
    Disclosure

    The attestation report was real. Signed by genuine hardware. It validated. The client still ended up talking to an attacker. CVE-2026-33697, in an attested TLS implementation. The evidence was bound to the ephemeral session key and not to the TLS channel: → extract that key and you can relay or divert the whole attested session → the client sees a real enclave with the right measurements and proceeds → the report cannot distinguish the genuine service from the relay Not an implementation bug. The subsystem was fully redesigned in v0.7.0 and the flaw survived it, because the design bound the wrong two things together. Researchers formally analysed seven intra-handshake binding designs in ProVerif and all seven fail the same way. Fixed in v0.9.0 with post-handshake binding. The scorers do not agree how bad it was. The CNA says 7.5, scope changed. NVD says 6.3, scope unchanged. That one metric is an argument about whether relaying an attested session escapes the boundary the attestation was supposed to establish. The honest limit, and it is mine. TRACE signs trust records so an auditor can prove one was not altered. It cannot prove the set is complete: route a call around the gateway and there is no record, and a missing record looks identical to an action that never happened. The verifier also checks against the issuer's own key, so a signature from my gateway is not something your incident responder can independently check. Signing is the easy part. Binding is where all of these fail. https://dev.to/mosiddi/what-a-signature-does-not-prove-314o

    Post summary

    The post discloses a design flaw in an attested TLS implementation (CVE-2026-33697), details the technical failure, notes a formal analysis, and reports a patch in v0.9.0, but provides no evidence of live exploitation or PoC code.

    0000062
    80 followersView on X
  • Muhammad Usama Sardar@M_UsamaSardar
    PoC

    @mosiddi Physical access is not required. You can break confidential computing without that. https://researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS https://github.com/muhammad-usama-sardar/intra-handshake.fail https://ietf.org/archive/id/draft-intra-handshake-fail-01.html https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7 https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h https://github.com/CCC-Attestation/attested-tls-poc/pull/58 https://cve.org/CVERecord?id=CVE-2026-33697

    Post summary

    The tweet announces CVE‑2026‑33697’s vulnerability, provides proof‑of‑concept and exploit code via multiple GitHub links, but does not mention active exploitation or any patch.

    0000047
    17 followersView on X
  • Muhammad Usama Sardar@M_UsamaSardar
    General

    @radian What mitigations are you using for the high-severity CVEs on attestation protocols? https://researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS https://github.com/muhammad-usama-sardar/intra-handshake.fail https://ietf.org/archive/id/draft-intra-handshake-fail-01.html https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7 https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h https://github.com/CCC-Attestation/attested-tls-poc/pull/58 https://cve.org/CVERecord?id=CVE-2026-33697

    Post summary

    The message is a query about mitigations for a high‑severity CVE and includes links to research, PoC code, IETF drafts, and advisories, but does not provide exploit details or patch information.

    0000046
    17 followersView on X
  • Muhammad Usama Sardar@M_UsamaSardar
    Exploit

    @veorq The marketing bubble has been shattered into pieces. The core trust mechanism is broken. https://researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS https://github.com/muhammad-usama-sardar/intra-handshake.fail https://ietf.org/archive/id/draft-intra-handshake-fail-01.html https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7 https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h https://github.com/CCC-Attestation/attested-tls-poc/pull/58 https://cve.org/CVERecord?id=CVE-2026-33697

    Post summary

    CVE‑2026‑33697 is a high‑severity vulnerability in Attested TLS with publicly available PoC and exploit code referenced in multiple repositories and advisories, though no active exploitation or patch details are disclosed.

    0000049
    17 followersView on X
  • Muhammad Usama Sardar@M_UsamaSardar
    PoC

    @jitusorkar12 @CNPYNetwork What mitigations are you using for the high-severity CVEs on attestation protocols? https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS https://github.com/muhammad-usama-sardar/intra-handshake.fail https://www.ietf.org/archive/id/draft-intra-handshake-fail-01.html https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7 https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h https://github.com/CCC-Attestation/attested-tls-poc/pull/58 https://www.cve.org/CVERecord?id=CVE-2026-33697

    Post summary

    The post references public PoC repositories and security advisories for CVE‑2026‑33697, indicating that proof‑of‑concept code exists, but it does not document active exploitation, an official patch, or technical vulnerability details.

    0000044
    17 followersView on X
  • NerdieNews@NewsNerdie
    Patch

    CVE-2026-33697: CoCoS's attested TLS is vulnerable to relay attacks due to weak ephemeral key handling, allowing attackers to intercept and manipulate data. Patch immediately to prevent unauthorized data access. #CyberSecurity #InfoSec https://t.co/1v5JVXBzpn

    Post summary

    The tweet announces a CVE with relay‑attack vulnerability and urges immediate patching, focusing on remediation rather than detailed technical exploitation.

    0000028
    53 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-33697 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33697 #CVE-2026-33697 #CVE #High #CyberSecurity #InfoSec https://t.co/N6I7JQPZr2

    Post summary

    A new CVE (CVE-2026-33697) has been announced with a severity score of 7.5; no additional technical details, PoC, exploitation evidence, or patch information is provided.

    0000039
    123 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appultravioletcocos_ai-go-

Explore more