Urgent.News

What's breaking now, across thousands of outlets.

Tech

Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug

The source material discusses a security vulnerability in the Raspberry Pi RP2350 microcontroller, which allows attackers to inject faults using a laser and photon-emission microscopy to manipulate debug registers. The chip's Secure debug feature is protected by a memory-mapped DEBUGEN register, which can be overridden by Secure software to enable access to Secure memory.

By using laser pulses and PEM, the researchers were able to set the DEBUGEN bits and restore debugger access to the chip's Secure world, even though debug had been permanently disabled. This allowed them to recover a secret from the chip's one-time-programmable memory and further investigate the security configuration and lock mechanisms.

The attack requires physical access, destructive preparation, and expensive laboratory equipment, but once the Secure debug path is compromised, the attacker can read and write Secure memory, halt and single-step a core, and inspect its registers.

Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at donjon.ledger.com →

More in Tech

More from Friday 18 September →