Source status: The Caliptra CVE records directly credit Alex Matrosov with Claude, Anthropic and publish fixed version boundaries. CNA scores are 5.6 and 1.8.
Summary
CVE-2026-11835 lets a compromised local controller exploit a staging-address TOCTOU condition to modify firmware after verification while attestation still reflects the verified digest. CVE-2026-11836 concerns missing per-device binding in production debug-unlock token verification.
Both records directly name Claude in the accepted disclosure credit.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.