XKEYCHAINX LABS
Jade / Public disclosure

Descriptor parsing memory corruption

Crash; potential secret-key extraction on exploitable versions.

Source date: 2025-12-16Reviewed: 11 October 2026

Affected scope

Firmware 1.0.24–1.0.36

What the attack requires

Initialized, unlocked device; malicious host on its selected USB/Bluetooth interface.

Response & remediation

What changed

1.0.37 fixes parsing; 1.0.38 adds rollback protection.

What this finding establishes

QR mode unaffected. Code execution on 1.0.36 was uncertain; no known active exploitation reported.