CVE-2026-14296

Nordic Semiconductor · nRF54H20

A vulnerability in the nRF54H20 Direct XIP update strategy allows the main application to start other cores using an unauthenticated slot, bypassing secure boot mechanisms.

Executive summary

The Nordic nRF54H20 contains a critical vulnerability in its update process that allows the execution of unauthenticated firmware, potentially leading to a complete compromise of the system.

Vulnerability

This vulnerability involves an improper verification of cryptographic signatures (CWE-347) during the boot process. When using the Direct XIP update strategy, the main application image fails to verify the authenticity of the slot used to start secondary cores, allowing an attacker to trigger the execution of code from an unauthenticated memory location.

Business impact

Successful exploitation allows an attacker to bypass secure boot mechanisms, which are foundational to device integrity. This could lead to unauthorized code execution, permanent device compromise, or the installation of persistent malicious firmware. With a CVSS score of 7.5, this high-severity flaw threatens the operational integrity of devices relying on the nRF54H20 platform.

Remediation

Immediate Action: Review the official Nordic Semiconductor documentation for available security updates and apply them to all affected nRF54H20 devices.

Proactive Monitoring: Monitor device boot logs and system initialization patterns for any deviations from standard startup procedures, particularly regarding core activation.

Compensating Controls: Ensure that physical access to the device is restricted and that debug interfaces are locked to prevent unauthorized modification of flash memory partitions.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of secure boot bypasses, organizations using the nRF54H20 should prioritize this update. Verify the firmware version on all deployed units and apply the vendor-provided patches immediately to ensure core execution integrity.

More Nordic Semiconductor CVEs

Sources

Originally found and disclosed by Reported externally through PSIRT, per the CVE Program record.