Meta and Cocos AI hit by high-severity intra-handshake attestation vulnerabilities
Security researchers have disclosed a high-severity vulnerability (CVE-2026-33697) in intra-handshake attestation protocols, affecting implementations from Meta AI, Cocos AI, and Edgeless Systems. The IETF draft recommends that developers transition to post-handshake attestation to mitigate relay attacks that current binding mechanisms fail to prevent.
Key Takeaways
- CVE-2026-33697 carries a CVSS score of 7.5, indicating a high-severity risk for attested TLS protocols.
- Vulnerable implementations include Meta AI's private processing whitepaper, Cocos AI, and Privasys rustls.
- Researchers found that intra-handshake attestation fails to achieve level 3 application-traffic binding, leaving it open to relay exploits.
- The IETF draft recommends an urgent transition to post-handshake attestation to ensure secure shared secrets.
Why It Matters
These intra-handshake attestation vulnerabilities represent a significant failure in the core trust mechanisms of confidential computing, which streaming platforms increasingly rely on for secure AI processing and DRM. The inability to bind evidence to application-level traffic means that even encrypted sessions can be redirected by attackers, undermining the digital sovereignty of B2B streaming infrastructure. As the industry shifts toward more complex AI-driven workflows, this discovery forces a re-evaluation of how identity and attestation are handled within the TLS handshake. Watch for the IETF SEAT working group to officially deprecate intra-handshake methods in favor of post-handshake attestation standards like draft-fossati-seat-expat.
Additional Context
The IETF SEAT working group has been actively standardizing attestation protocols for confidential computing environments. In early 2026, the group published draft-fossati-seat-expat as a post-handshake attestation framework designed to decouple attestation evidence from the TLS handshake itself, a direct architectural response to the relay attack surface that CVE-2026-33697 exposes. Edgeless Systems, one of the affected vendors, has been a prominent contributor to confidential computing tooling through its Contrast Security platform, which provides runtime attestation for Kubernetes workloads. Edgeless Systems raised a $25 million Series A in late 2024 to expand its confidential computing platform across enterprise deployments, positioning itself as a key infrastructure provider for organizations that need hardware-backed isolation guarantees. On the regulatory and business side, the EU Cyber Resilience Act, which entered into force in December 2024, imposes mandatory vulnerability disclosure obligations on manufacturers of products with digital elements sold in the European market, creating compliance pressure for vendors like Cocos AI and Privasys that ship attestation-enabled software stacks. The act's 24-hour initial reporting window for actively exploited vulnerabilities means that high-severity findings such as CVE-2026-33697 carry immediate legal consequences for affected vendors operating in EU jurisdictions. Meanwhile, the Confidential Computing Consortium, hosted under the Linux Foundation, expanded its membership to over 30 organizations in 2025, including cloud providers and hardware vendors, signaling that the industry recognizes attestation as a foundational trust layer rather than a niche security feature. From a technical standpoint, the rustls library, which underpins several affected implementations, has been undergoing active development to support post-handshake attestation extensions. Rustls maintainers merged support for the TLS 1.3 certificate compression extension in mid-2025, reducing handshake overhead and creating space for additional attestation messages without performance penalties. Muhammad Usama Sardar, the lead researcher behind the CVE-2026-33697 disclosure, previously published work on formal verification of attestation protocols at TU Dresden, and his team demonstrated that relay attacks could succeed against three independent implementations with as few as two network-level manipulations, underscoring that the vulnerability class is systemic rather than implementation-specific. Carina Hilt, co-author on the IETF draft, has contributed to the SEAT working group's threat model documentation since its chartering in 2024.
Read full article at datatracker.ietf.org
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source