• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
Sq Magazine LogoSQ Magazine

Smarter Insights for a Fast-Moving Digital World

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Sq Magazine Logo
  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Home » Cybersecurity

UEFI Flaw Lets Hackers Bypass Secure Boot on 200,000 Framework Laptops

Published on: October 15, 2025
Sofia Ramirez
Written By
Sofia Ramirez
Sofia Ramirez
Senior Tech Writer • 435 Articles
Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps reader...
LATEST POSTS:
Hackers Abuse Microsoft Teams to Conceal Ransomware Activity
FBI Destroys Massive AI Phishing Empire Linked to $1.9B Theft
ShinyHunters Targets Council of Europe in Major Cyberattack
Uefi Shell Vulnerability In Framework Laptops
As Featured In
The New York Times LogoForbes LogoWired LogoDeloitte LogoResearch.com Logo
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

A major firmware vulnerability has put over 200,000 Framework laptops and desktops at risk by allowing hackers to bypass Secure Boot protections using trusted diagnostic tools.

Quick Summary – TLDR:

  • Signed UEFI shells distributed by Framework can disable Secure Boot through memory modification commands.
  • Hackers can exploit this flaw to load bootkits or rootkits that persist undetected across reboots.
  • Framework has released firmware updates and revocation lists to fix the issue across affected models.
  • The flaw reveals deeper industry-wide challenges in trusting signed pre-boot components.

What Happened?

Researchers at Eclypsium found that legitimate UEFI diagnostic shells distributed by Framework include a powerful command that can disable Secure Boot, a key security feature that ensures only trusted code runs during system startup. These shells, signed with Microsoft-trusted certificates, allow memory manipulation that could lead to deeply persistent, undetectable malware infections.

Trust is something earned, except in the case of Secure Boot, where trust is often overlooked and never verified. Enter UEFI shells, included in many system utilities, have to be signed to work with Secure Boot. Functionality in UEFI shells allows attackers to bypass Secure Boot.… pic.twitter.com/A7JwFodFsF

— Paul Asadoorian @paulasadoorian@infosec.exchange (@securityweekly) October 14, 2025

Signed Tools Open the Door to Pre-Boot Attacks

Framework, known for its repairable and customizable laptops, offers UEFI shells primarily to help Linux users perform firmware updates. However, these tools include the mm command, which enables direct access to system memory. While useful for debugging, this command can also be used to overwrite memory addresses tied to Secure Boot enforcement, such as the gSecurity2 variable.

By modifying or nullifying this pointer, attackers can trick the system into believing Secure Boot is enabled even while loading unsigned code. This undermines the entire boot security chain, potentially allowing bootkits or rootkits to run with no warnings or errors reported to the operating system.

How the Attack Works?

Eclypsium researchers Jesse Michael and Mickey Shkatov showcased this technique, which involves:

  • Launching the signed UEFI shell before the OS boots.
  • Using shell commands to locate the Security Architectural Protocol.
  • Running the mm command to alter the memory where signature checks happen.
  • Disabling verification for any unsigned modules or code.

Attackers can automate this using startup scripts in the UEFI environment, ensuring persistence across reboots.

Newsletter
Subscribe To Our Newsletter!

Be the first to get exclusive offers and the latest news.

Real-World Impact and Threat Actors

Testing confirmed that Framework devices across multiple generations, including Intel Core and AMD Ryzen models, were affected. Using QEMU environments, sbverify, and Python scripts, researchers verified the presence of the mm command and demonstrated how easily the flaw could be exploited.

While no specific malware campaign has been directly linked to this vulnerability, similar Secure Boot bypasses have been used by ransomware like HybridPetya and offered by gaming cheat vendors. The existence of commercial tools selling for as much as 40 euros a month shows this is far from a theoretical issue.

More worryingly, the attack surface is appealing for nation-state actors and advanced persistent threats. Exploiting the trust placed in Microsoft-signed components, attackers can gain a foothold that’s almost invisible to traditional security tools.

Framework’s Response and Fixes

Framework has acknowledged the problem and is working actively to roll out fixes. Several BIOS updates have been released to remove the mm command from UEFI shells and update the DBX revocation list to blacklist vulnerable binaries.

Firmware Updates and Status by Model:

  • Intel 13th Gen: Fixed in version 3.08 and DBX fix in 3.09.
  • Intel 12th Gen: Shell fixed in 3.18, DBX fix planned for 3.19.
  • Intel 11th Gen: Fix coming in version 3.24.
  • AMD Ryzen 7040 Series: Fixed in version 3.16.
  • AMD Ryzen AI 300 Series: Fix in 3.04, DBX update in 3.05 (planned).
  • Framework 16 and Desktop models: Fixes included in latest beta versions or upcoming updates.

Framework also recommends that users manually delete the DB keys through BIOS setup to revoke trust for older UEFI shells. Detailed support resources are being made available for affected users.

SQ Magazine’s Takeaway

I find this case especially alarming because it shatters the long-held belief that signed means safe. Framework didn’t do anything shady, yet trusted tools became a liability due to how deeply Secure Boot trusts them. It’s a reminder that security isn’t just about locking the doors but checking who holds the keys. As users, we often assume firmware is safe if it looks official, but this proves that even the cleanest intentions can open dangerous holes. I strongly recommend updating your BIOS if you use a Framework device and start treating your firmware like the critical layer of defense it really is.

SQ Magazine follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add SQ Magazine as a Preferred Source on Google for updates! Follow on Google News
Share ChatGPT Perplexity
Sofia Ramirez

Sofia Ramirez

Senior Tech Writer


Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps readers stay informed and secure in today’s fast-changing tech landscape. Passionate about making cybersecurity accessible, Sofia blends research-driven analysis with straightforward explanations; so whether you’re a tech professional or a curious reader, her work ensures you’re always one step ahead in the digital world.

Related Posts

Ledger Researchers Find Android Bug That Risks Crypto Wallets
Cybersecurity

Ledger Researchers Find Android Bug That Risks Crypto Wallets

Ubuntu Security Flaw Lets Hackers Gain Root Control
Cybersecurity

Ubuntu Security Flaw Lets Hackers Gain Root Control

Fragnesia Exploit Threatens Major Linux Distributions
Cybersecurity

Fragnesia Exploit Threatens Major Linux Distributions

Disclaimer: The content published on SQ Magazine is for informational and educational purposes only. Please verify details independently before making any important decisions based on our content.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

GPUBreach Attack Enables Full System Takeover via GPU
New Dirty Frag Exploit Puts Millions of Linux Systems at Risk
Critical Argument Injection Flaw Lets Hackers Hijack AI Agents

Table of Contents

  • Quick Summary – TLDR:
  • What Happened?
  • Signed Tools Open the Door to Pre-Boot Attacks
  • How the Attack Works?
  • Real-World Impact and Threat Actors
  • Framework’s Response and Fixes
  • SQ Magazine’s Takeaway
Connect on Telegram

Footer

SQ Magazine Logo

Smarter Insights for a Fast-Moving Digital World

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer

Worth Checking

  • Social Media Attention Span Stats
  • Reddit Statistics
  • Spotify User Statistics
  • TikTok vs. Instagram Statistics
  • Gen Z Social Media Statistics
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. – 6 p.m. | Every day

Copyright © 2022–2026 SQ Magazine. All Rights Reserved. Powered by the Neural Stack.

  • Privacy Policy
  • Terms
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • Brand Assets
    Brand Assets
  • Stats Methodology
    Stats Research Process
  • Glossary
    Glossary
Categories
  • Internet
  • Gaming
  • Technology
  • Artificial Intelligence
  • Cybersecurity
Internet
YouTube vs TikTok Statistics 2026: Users, Revenue, Creator Economy
YouTube vs TikTok Statistics 2026: Users, Revenue, Creator Economy
Internet Outage Statistics 2026: Frequency, Cost and Causes
Internet Outage Statistics 2026: Frequency, Cost and Causes
Upwork Statistics 2026: Revenue, GSV, AI Work
Upwork Statistics 2026: Revenue, GSV, AI Work
Instagram Reels Statistics 2026: Plays and Engagement
Instagram Reels Statistics 2026: Plays and Engagement
Gig Economy Statistics 2026: Workforce & Earnings
Gig Economy Statistics 2026: Workforce & Earnings
Doomscrolling Statistics: Prevalence, Sleep and Mental Health
Doomscrolling Statistics: Prevalence, Sleep and Mental Health
Gaming
Online Gambling Regulations Statistics 2026: Global Compliance and Enforcement Data
Online Gambling Regulations Statistics 2026: Global Compliance and Enforcement Data
Fantasy Sports Statistics 2026: Users, Revenue & Trends
Fantasy Sports Statistics 2026: Users, Revenue & Trends
Apex Legends Statistics 2026: Players, Revenue, and Esports
Apex Legends Statistics 2026: Players, Revenue, and Esports
Fortnite Statistics 2026: Players, Revenue, Esports, and Engagement
Fortnite Statistics 2026: Players, Revenue, Esports, and Engagement
Gamers Statistics 2026: Players, Habits & Global Data
Gamers Statistics 2026: Players, Habits & Global Data
Minecraft Statistics 2026: 300 Million Copies Sold & 212M Monthly Players
Minecraft Statistics 2026: 300 Million Copies Sold & 212M Monthly Players
Technology
Employee Productivity Statistics 2026: Engagement, Costs & Trends
Employee Productivity Statistics 2026: Engagement, Costs & Trends
Software Engineer Layoff Statistics 2026: Companies, Roles, AI Impact
Software Engineer Layoff Statistics 2026: Companies, Roles, AI Impact
iPhone Ecosystem Statistics 2026: Big Market Trends
iPhone Ecosystem Statistics 2026: Big Market Trends
Average Screen Time by Age Statistics 2026: Latest Insights
Average Screen Time by Age Statistics 2026: Latest Insights
AI SEO Statistics 2026: Adoption, AI Overviews & LLM Citation Data
AI SEO Statistics 2026: Adoption, AI Overviews & LLM Citation Data
Digital Nomads Statistics 2026: Population, Demographics & Visa Data
Digital Nomads Statistics 2026: Population, Demographics & Visa Data
Artificial Intelligence
AI Image Generation Statistics 2026: Market Size, Adoption & Risks
AI Image Generation Statistics 2026: Market Size, Adoption & Risks
AI Influencer Marketing Statistics: Market Size and Engagement
AI Influencer Marketing Statistics: Market Size and Engagement
AI Market Statistics 2026: Size, Growth & Investment
AI Market Statistics 2026: Size, Growth & Investment
Meta AI Statistics 2026: Users, Capex, and Adoption Data
Meta AI Statistics 2026: Users, Capex, and Adoption Data
Predictive AI Statistics 2026: Market Size, Adoption & Accuracy Data
Predictive AI Statistics 2026: Market Size, Adoption & Accuracy Data
AI Overviews Statistics 2026: Google Search Impact Data
AI Overviews Statistics 2026: Google Search Impact Data
Cybersecurity
Password Statistics 2026: Credential Theft, MFA, and the Passkey Tipping Point
Password Statistics 2026: Credential Theft, MFA, and the Passkey Tipping Point
Identity Theft Statistics 2026: Key Fraud Data and Trends
Identity Theft Statistics 2026: Key Fraud Data and Trends
CVE Statistics 2026: Severity Distribution and Top Affected Vendors
CVE Statistics 2026: Severity Distribution and Top Affected Vendors
Dark Web AI Tool Marketplace Statistics 2026: Explosive Market Growth
Dark Web AI Tool Marketplace Statistics 2026: Explosive Market Growth
API Security Breach Statistics 2026: Hidden Threats
API Security Breach Statistics 2026: Hidden Threats
AI Voice Cloning Fraud Statistics 2026: Alarming Trends You Must Know Now
AI Voice Cloning Fraud Statistics 2026: Alarming Trends You Must Know Now
Categories
  • Internet
  • Gaming
  • Technology
  • Artificial Intelligence
  • Cybersecurity
Internet
Telegram Restricted in India as NEET Fraud Crackdown Grows
Telegram Restricted in India as NEET Fraud Crackdown Grows
UK Unveils Under 16 Social Media Ban With Tough New Rules
UK Unveils Under 16 Social Media Ban With Tough New Rules
Facebook and Instagram Hit by Major Global Outage
Facebook and Instagram Hit by Major Global Outage
Pinterest Bets Big on AI With Record $4B AWS Commitment
Pinterest Bets Big on AI With Record $4B AWS Commitment
Lovable Expands Google Cloud Deal, Boosts AI Infrastructure 5x
Lovable Expands Google Cloud Deal, Boosts AI Infrastructure 5x
Shopify Down: Thousands Report Outage and Checkout Issues
Shopify Down: Thousands Report Outage and Checkout Issues
Gaming
Epic Games Teases Unreal Engine 6 for Rocket League
Epic Games Teases Unreal Engine 6 for Rocket League
Stardew Valley Switch 2 Edition Arrives with Online Co-op
Stardew Valley Switch 2 Edition Arrives with Online Co-op
Hogwarts Legacy Crosses 40M Sales, Beating Industry Giants
Hogwarts Legacy Crosses 40M Sales, Beating Industry Giants
PUBG: Black Budget Launches Closed Alpha Test With a Bold PvPvE Twist
PUBG: Black Budget Launches Closed Alpha Test With a Bold PvPvE Twist
Counter-Strike 2’s $5.9 Billion Skin Economy Just Got Shattered
Counter-Strike 2’s $5.9 Billion Skin Economy Just Got Shattered
Battlefield 6 Outperforms Franchise Past with Record-Breaking Launch
Battlefield 6 Outperforms Franchise Past with Record-Breaking Launch
Technology
Android 17 Is Here With Powerful AI Features and Security Boosts
Android 17 Is Here With Powerful AI Features and Security Boosts
Telegram Returns to Wear OS With Smartwatch App Upgrade
Telegram Returns to Wear OS With Smartwatch App Upgrade
Apple Announces macOS 27 Golden Gate at WWDC 2026
Apple Announces macOS 27 Golden Gate at WWDC 2026
Apple iPadOS 27 Introduces New Siri App and Productivity Tools
Apple iPadOS 27 Introduces New Siri App and Productivity Tools
Microsoft Reveals Xbox Series X25 Limited Edition Console
Microsoft Reveals Xbox Series X25 Limited Edition Console
Leaked iOS 27 Features Include AI Siri and More iPhone Support
Leaked iOS 27 Features Include AI Siri and More iPhone Support
Artificial Intelligence
SpaceX Makes Bold $60 Billion Bet on Cursor AI
SpaceX Makes Bold $60 Billion Bet on Cursor AI
Sarvam Becomes AI Unicorn After Massive $234M Funding Round
Sarvam Becomes AI Unicorn After Massive $234M Funding Round
Anthropic Introduces Age Checks and ID Verification for Claude
Anthropic Introduces Age Checks and ID Verification for Claude
New Kimi K2.7 Code Promises Faster AI Coding Workflows
New Kimi K2.7 Code Promises Faster AI Coding Workflows
US Blocks Anthropic Fable 5 Access Over Security Fears
US Blocks Anthropic Fable 5 Access Over Security Fears
McDonald’s Tests Powerful New AI Drive Thru With Google
McDonald’s Tests Powerful New AI Drive Thru With Google
Cybersecurity
Hackers Abuse Microsoft Teams to Conceal Ransomware Activity
Hackers Abuse Microsoft Teams to Conceal Ransomware Activity
FBI Destroys Massive AI Phishing Empire Linked to $1.9B Theft
FBI Destroys Massive AI Phishing Empire Linked to $1.9B Theft
ShinyHunters Targets Council of Europe in Major Cyberattack
ShinyHunters Targets Council of Europe in Major Cyberattack
Urgent Oracle PeopleSoft Flaw Linked to ShinyHunters Campaign
Urgent Oracle PeopleSoft Flaw Linked to ShinyHunters Campaign
73,000 French Government Accounts Exposed in Tchap Breach
73,000 French Government Accounts Exposed in Tchap Breach
High Risk Microsoft Teams Android Bug Could Leak Sensitive Data
High Risk Microsoft Teams Android Bug Could Leak Sensitive Data
Newsletter

Subscribe To Our Newsletter!

Be the first to get exclusive offers and the latest news.

Newsletter

Subscribe To Our Newsletter!

Be the first to get exclusive offers and the latest news.