Executive brief
A security flaw in Silicon Labs EFR32xG27 wireless chips causes the device to generate predictable security keys. These chips are commonly used in IoT devices for wireless communication; if an attacker can predict these keys, they may be able to decrypt sensitive data or bypass security protections. This issue stems from how the hardware's 'unclonable' security feature was implemented in the software development kit.
Technical details
A vulnerability exists in the Silicon Labs SiSDK (versions up to 2025.12.1) affecting EFR32xG27 wireless SoCs. The root cause is the incorrect use of the Physically Unclonable Function (PUF) key during the user key generation process, which results in a small seed space (CWE-339). This flaw makes the resulting cryptographic keys predictable. An attacker with adjacent network access could potentially exploit this to compromise the confidentiality and integrity of the device's secure communications. The issue is addressed in newer versions of the SiSDK.
Affected products
- Silicon Labs SiSDK <= 2025.12.1
- Silicon Labs EFR32xG27 Wireless SoC
Timeline
- 2026-06-25: advisory
- 2026-06-25: disclosed