EU Age Verification App: A Systemic Architectural Failure

Beyond the Surface: From Client-Side Logic Bypass to Biometric Trust Chain Collapse

Author: Zampier Zago - Independent Security Researcher

Date: April 19, 2026

Target: eu.europa.ec.eudi.wallet.av (Pilot Build 2026.04-2)

TLP: WHITE - May be freely shared

Abstract

This paper presents an independent technical analysis of the EU Age Verification app (EUDI Wallet Pilot, build 2026.04-2). The research uncovers a systemic architectural failure where the entire biometric verification pipeline—including liveness detection, face matching, and credential binding—executes without any hardware root of trust, TEE isolation, or cryptographic attestation of the sensor chain.

The full document maps out four escalating vulnerability tiers demonstrating that the application's security guarantees are architecturally unenforceable. This impacts not just this pilot app, but the entire EUDI Wallet framework and technical standards tied to the Digital Services Act.

Download Full PDF Whitepaper

(Format: PDF)