Junglewise Threat Intelligence

CVE-2026-18796: Nordic Semiconductor nRF5340 external QSPI flash encryption weakness

CVE-2026-18796 · Severity: info · Published 2026-09-07

Executive brief

The nRF5340 microcontroller's external QSPI flash encryption mechanism for execute-in-place (XIP) code contains a fundamental weakness in its on-the-fly decryption scheme. Applications relying on this encryption to protect externally stored code confidentiality or integrity are exposed to potential data leakage or code tampering. An attacker with physical access to the QSPI flash storage could potentially read or modify encrypted code without requiring the encryption key.

Technical details

This vulnerability exists in the on-the-fly decryption scheme used by the nRF5340 for external QSPI flash XIP (Execute In Place) operations, affecting all applications that depend on this encryption for code confidentiality or integrity protection. The weakness is not version-specific to nRF Connect SDK but rather a fundamental design flaw in how the decryption mechanism operates. The attack vector requires physical access to the QSPI flash memory and knowledge of the encryption scheme. An attacker can leverage this weakness to decrypt stored code, extract sensitive firmware logic, or inject modified code into the flash storage. No patch status is currently documented, as this represents an architectural limitation rather than a traditional software bug.

Affected products

  • Nordic Semiconductor nRF5340 all versions

Timeline

  • 2026-09-07: disclosed

References