Academic researchers disclosed a fundamental weakness in attested TLS, the remote attestation mechanism used by confidential computing platforms to prove a server is running inside a trusted execution environment (TEE). The team, led by Muhammad Usama Sardar of TU Dresden, found that current intra-handshake attestation designs do not securely bind attestation evidence to the actual TLS connection, enabling relay or diversion attacks in which a client validates a genuine attested server or AI agent but unknowingly sends encrypted traffic to a different malicious machine. The issue has been assigned CVE-2026-33697 and rated high severity.
The researchers formally analyzed seven cryptographic binding approaches and reported that none prevented this attack class, raising concerns that stronger “level-three” binding may be unattainable within the current architecture. Reported affected implementations include Meta’s Private Processing for WhatsApp, Edgeless Systems’ Contrast, Cocos AI, and a Confidential Computing Consortium proof of concept. Standards groups including the IETF SEAT and TLS working groups have acknowledged the findings, while the researchers recommended moving away from intra-handshake attestation toward post-handshake attestation as a safer alternative.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The IETF SEAT and TLS working groups acknowledged the reported attacks against attested TLS. Researchers argued that level-three binding may be unattainable in current intra-handshake attestation designs and recommended post-handshake attestation instead.
The research identified further real-world systems affected by CVE-2026-33697, including Cocos AI and a Confidential Computing Consortium proof of concept, in addition to previously cited implementations. The article states that Cocos AI versions 0.4.0 through 0.8.2 were explicitly impacted.
The disclosed flaw affecting confidential computing implementations was assigned CVE-2026-33697 and described as impacting real-world systems including Meta's Private Processing for WhatsApp and Edgeless Systems' Contrast. One source states the issue was rated 7.5 in severity.
Academic research led by Muhammad Usama Sardar found relay and diversion weaknesses in attested TLS, showing that current intra-handshake attestation schemes do not securely bind attestation evidence to the actual TLS connection. The work reported that multiple binding methods were evaluated and none prevented this class of attack.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetheregister.com
Open sourcetheregister.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.