Overview
A software vulnerability - CVE-2026-87726 - has been identified in the supporting software NXPNfcRdLib. An insufficient API bounds checking in NXP NXPNfcRdLib module phalFelica up to Firmware version 07.14.00_Pub may allow an attacker with privileges or an untrusted third party to access unintended memory regions, potentially leading to limited loss of confidentiality, integrity, and availability.
Impacted devices
The vulnerability affects deployments of NXPNfcRdLib versions 07.14.00 and earlier when used in conjunction with FeliCa-based applications on NFC Reader solutions built on the CLRC663 family, PN5180, PN7462, and PN5190 platforms.
Mitigation
Use the latest NXPNfcRdLib available on NFC Reader Library | NXP Semiconductors All firmware versions from 07.18.00 onwards have fixed this problem.
Acknowledgment
NXP would like to thank Ezhilamuthan for the responsible disclosure.