All findings

CVE-2026-11835, CVE-2026-11836 medium

Caliptra directly credits Claude on two secure-boot and debug-unlock flaws

Caliptra's CNA records credit Alex Matrosov with Claude, Anthropic on a secure-boot TOCTOU bypass and a device-binding weakness.

Bug class
Secure-boot TOCTOU bypass and production debug-token device-binding weakness
Affected codebase
Caliptra Core ROM and firmware
Credited system
Claude / Anthropic Research
Disclosed
August 4, 2026
Attribution
Direct source attribution
Severity
medium
Source status: The Caliptra CVE records directly credit Alex Matrosov with Claude, Anthropic and publish fixed version boundaries. CNA scores are 5.6 and 1.8.

Summary

CVE-2026-11835 lets a compromised local controller exploit a staging-address TOCTOU condition to modify firmware after verification while attestation still reflects the verified digest. CVE-2026-11836 concerns missing per-device binding in production debug-unlock token verification.

Both records directly name Claude in the accepted disclosure credit.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.