• 0 Posts
  • 2 Comments
Joined 2 years ago
cake
Cake day: June 1st, 2023

help-circle

  • The security researcher, LimitedResults, coordinated disclosure with Espressif on their advisory and details of the exploit. The attack works against eFuse, a one-time programmable memory where data can be burned to the device.

    By burning a payload into the device’s eFuse, no software update can ever reset the fuse and the chip must be physically replaced or the device discarded. A key risk is that the attack does not fully replace the firmware, so the device may appear to work as normal.

    Why does a random esp32 chip need efuses in the first place??