Urgent.News

What's breaking now, across thousands of outlets.

Tech

The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026 [32:37]

In 2025, I [the speaker] found and disclosed a bunch of vulnerabilities in GPG, the most used PGP implementation, and held a talk at 39c3 about it. Some of the bugs ended up getting fixed. This talk describes the adventure and aftermath of getting there, shows some novel ones, and talks about the state of security in 2026. May contain zero-days =) Until May 2025, I liked PGP, and the GNU Privacy…

In 2025, the speaker discovered and disclosed multiple vulnerabilities in GPG, the most widely used PGP implementation. Some of these bugs were later fixed. The speaker held a talk at 39c3 to describe the experience and aftermath of finding these vulnerabilities, showcasing novel ones and discussing the current state of security in 2026.

At the time, the speaker had a positive view of PGP and the GNU Privacy Guard, but their perspective changed after uncovering a vulnerability that allowed easy spoofing of PGP signatures when naively opened with GPG. This vulnerability eventually evolved into several independent ones, including a memory corruption issue in the basic PGP message parser that affected nearly all PGP-related workflows. The speaker disclosed these vulnerabilities a few weeks before 39c3 in December 2025.

While some of the vulnerabilities, such as the memory corruption bug, were addressed properly, others were not. For instance, one of the initial vulnerabilities used for the introduction hook in the 39c3 talk remains unpatched. Instead of promptly fixing the code, the main developer of GnuPG, Werner Koch, published a blog post in December 2025 declaring the widely-used feature harmful, which was shared on the first day of 39c3, leaving no time for a response from the speaker and others. Several disgruntled comments followed, but many of the flaws still remain unaddressed.

In the talk, the speaker demonstrated the real impact of the footguns (unaddressed issues) in GPG, without using any zero-day vulnerabilities. They showed how severe the problem of these unpatched flaws truly is. Additionally, the speaker presented several novel vulnerabilities in GPG, which while not as impactful as the previous examples, are still significant bugs that should not have been present in the production code.

The talk concluded with general commentary on the state of security and responsible disclosure, as well as the role of AI/LLMs in security, using the gpg.fail vulnerabilities as examples. The speaker emphasized that while end users and security researchers are not doomed, both groups need to take the situation seriously.

Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at media.ccc.de →

More in Tech

Your Smart TV May Be Screenshotting Your Screen Every Half Second

What the research found A 2024 study by researchers at UC Davis, University College London, and Universidad Carlos III de Madrid audited the network traffic leaving Samsung and LG smart TVs, examining…

  • Smart TVs screenshot screens every 500ms, according to 2024 study
  • Samsung and LG settle lawsuit, stop collecting ACR data without consent
  • Disabling ACR complex, requires navigating multiple settings and menus

More from Saturday 12 September →