Private reporting channel for EMV .nfc file heap-buffer-overflow in NFC loader
Author: damselengCreated Jun 4, 2026Updated Jul 11, 2026
Labelsnfc
I found a reproducible heap-buffer-overflow write in the EMV .nfc file loading path. It is reachable from an externally supplied Flipper NFC device file with Device type: EMV and reproduces on dev and mntm-012. I have a minimized reproducer, ASan/plain logs, and suggested fix details. Could you please let me know the preferred private security reporting channel, or enable GitHub Private Vulnerability Reporting?
Source: Next-Flip/Momentum-Firmware