Junglewise Threat Intelligence

CVE-2026-18349: Microchip SAMA5D4 improper protection against voltage and clock glitches

CVE-2026-18349 · Severity: info · Published 2026-08-24

Executive brief

The Microchip SAMA5D4 is a system-on-chip processor used in embedded and IoT devices. This vulnerability allows an attacker with physical access to perform hardware fault injection attacks by exploiting insufficient protection against voltage and clock glitches, potentially bypassing security mechanisms and compromising device integrity.

Technical details

The SAMA5D4 microcontroller lacks adequate countermeasures against fault injection attacks via voltage and clock manipulation. This is a hardware-level vulnerability where insufficient glitch detection and prevention allows an attacker with physical access to the device to induce faults during cryptographic operations or security-critical code execution. An attacker can exploit this to bypass authentication, extract secrets, or execute unauthorized code. The attack requires direct physical access to the device and knowledge of timing or power characteristics. Microchip has acknowledged this issue but specific patch details are not publicly available in the accessible references.

Affected products

  • Microchip SAMA5D4

Timeline

  • 2026-08-24: disclosed

References