Skip to main content

Amazon Bee Private Compute

Type

Security review

Client

Amazon

Date

2026-09

Domain

AppSec

Effort

8 wks

Section

Technology Product Reviews

Trail of Bits's security review of Amazon (Sep 2026) identified 21 issues: 7 high, 7 medium, 2 low, and 5 informational.

Findings · 21

  1. 1 Legacy boot path executes code outside measurement context High
  2. 2 Sigstore context is never policy-enforced Medium
  3. 3 Application data disks are mounted by device path without measured or CVM-bound protection High
  4. 4 Android RFC 3161 timestamp verification can fail open and accept attacker-chosen verification time Medium
  5. 5 AMI Rekor entries are never signature-verified or bound to the transparency team signing certificate High
  6. 6 Go proxy accepts NitroTPM COSE_Sign1 payloads without signature verification High
  7. 7 Shared LLM prefix caches are not isolated across users High
  8. 8 Shared CVM Redis access is not scoped by service identity Informational
  9. 9 Bee Private Compute server derives deterministic CTR keys for BLE with insufficient checks Medium
  10. 10 Client attestation failures do not block key release High
  11. 11 Paired-app developer tokens lack scoped permissions Low
  12. 12 Conversation summaries are stored unencrypted in the search index Medium
  13. 13 Risk of container environment-variable injection via AWS Secrets Manager that can bypass the attestation chain High
  14. 14 Confidential VM image includes unnecessary packages Informational
  15. 15 APNs proxy Lambda logs notification content and request payloads Medium
  16. 16 Internal networking policy is overly lax for the Confidential VM tier Informational
  17. 17 Internal security controls for user data are overly lax Medium
  18. 18 Integration APIs receive user data without a sharing-consent check Medium
  19. 19 Push notifications routed to other users are sent in plaintext Low
  20. 20 Consent proof is generated server-side, not by the client as documented Informational
  21. 21 Ambiguous measurement serialization lets distinct configurations collide Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related