2026-10-29 –, Main Hall
Fault injection campaigns normally require a lengthy, complex process that can be difficult to reproduce. Finding trigger timings often requires extended research on the target's power consumption and side-channel analysis.
While trying to reproduce CVE-2020-27211 by LimitedResults, I discovered a novel, triggerless runtime attack on Nordic Semi's nRF52810 System-on-Chip (SoC) using electromagnetic (EM) fault injection. Unlike conventional approaches, this technique requires neither precise timing nor accurately synchronized EM pulses, making it remarkably simple and reproducible. Given the correct injection location, the attack succeeds on average with the first pulse. This is the first triggerless runtime attack ever reported.
I will walk you through the research process and discuss where this work could lead next.
This issue was recognized by Toreon as CVE-2025-9709.
Milena aka g0mb4ck is a Hardware Security Researcher and has just started her journey in Keysight Device Security, formerly known as Riscure B.V.
Her main focus is on fault injection, which is a way to test and break hardware security. Her goal is to really understand how these attacks work so she can help design better defenses.