Junglewise Threat Intelligence

CVE-2026-89172: Microchip AN1044, AN953, and SW300052 physical side-channel vulnerability

CVE-2026-89172 · Severity: info · Published 2026-09-12

Executive brief

Microchip application notes and software contain improper protections against physical side-channel attacks, which could allow an attacker with direct physical access to extract sensitive information such as cryptographic keys or other protected data. This vulnerability typically requires specialized hardware and lab-level physical access to exploit, but poses a risk to systems handling sensitive cryptographic operations.

Technical details

The vulnerability is classified as improper protection of physical side channels, a class of attack that exploits information leakage through physical phenomena (such as power consumption, timing, electromagnetic emissions, or acoustic emissions) to deduce secrets during cryptographic operations. The affected components are Microchip application notes AN1044 and AN953, and software package SW300052 through version 2.6. Exploitation requires physical proximity to the device and specialized measurement equipment; the vulnerability does not require network access or prior authentication. An attacker with physical access could potentially recover cryptographic keys or other sensitive data by analyzing side-channel emissions. Patch or mitigation guidance from Microchip is recommended for affected deployments.

Affected products

  • Microchip AN1044 through A
  • Microchip AN953 through A
  • Microchip SW300052 through 2.6

Timeline

  • 2026-09-12: disclosed

References