Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
embedded-device-vulnerabilitypersistence-methodendpoint-security-bypasswidely-deployed-product-advisory

Secure Boot Bypass Vulnerability in Framework Linux Laptops via Signed UEFI Shells

Updated 3mo agoFirst seen Oct 14, 20256 sources

Researchers from Eclypsium discovered that nearly 200,000 Linux-based Framework laptops and desktops were shipped with signed UEFI shell components containing a powerful 'memory modify' (mm) command, which can be exploited to bypass Secure Boot protections. The mm command, intended for low-level diagnostics and firmware debugging, provides direct read and write access to system memory, including critical security variables such as gSecurity2. By abusing this command, an attacker can overwrite the gSecurity2 variable with NULL, effectively disabling signature verification for all subsequent UEFI module loads and breaking the Secure Boot trust chain. This vulnerability allows attackers to load bootkits such as BlackLotus, HybridPetya, and Bootkitty, which can evade operating system-level security controls and persist even after OS reinstallation. The attack can be automated using startup scripts, ensuring persistence across reboots. The issue is not the result of a supply chain compromise or malicious intent, but rather an oversight in the inclusion of diagnostic tools signed with trusted certificates. Eclypsium's research highlights that these signed UEFI shells, while legitimate, function as backdoors that undermine the security model of Secure Boot. The presence of such tools in production devices exposes users to significant risk, as attackers can leverage them for pre-OS infections, espionage, sabotage, or ransomware attacks. The gaming industry has already seen commercial cheat providers exploiting similar UEFI-level bypasses, and the same techniques could be adopted by nation-state actors or advanced persistent threats. Framework has acknowledged the issue and is working on remediation, with fixes planned for affected models such as the Framework 13 (11th and 12th Gen Intel). The discovery underscores the broader risk of trusted, signed components containing powerful functionality that can be misused, and the need for rigorous review of firmware-level tools included in shipping devices. The vulnerability demonstrates that even systems marketed as secure and repairable can harbor critical flaws if diagnostic utilities are not properly restricted. The incident serves as a warning to hardware manufacturers and the security community about the dangers of trusted but overly permissive firmware components. Eclypsium's findings have prompted a reassessment of trust models in firmware security, emphasizing the importance of minimizing attack surfaces in pre-boot environments. The case also illustrates how attackers are increasingly targeting lower layers of the computing stack to achieve persistence and evade detection. Framework's response and the ongoing remediation efforts will be closely watched by the industry as a test case for responsible disclosure and mitigation of firmware-level threats.

Share:
Secure Boot Bypass Vulnerability in Framework Linux Laptops via Signed UEFI Shells
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Oct 14, 20258mo ago

Framework begins rolling out BIOS and DBX updates to mitigate the issue

Framework started releasing BIOS updates and DBX revocation-list updates to remediate affected devices and block vulnerable signed components. The response was part of coordinated mitigation following public disclosure of the Secure Boot bypass risk.

Eclypsium publicly discloses the 'BombShell' Framework firmware issue

Eclypsium published research detailing the 'BombShell' issue, explaining how the signed UEFI shells on Framework devices could allow direct memory modification, pre-boot code execution, and persistence while appearing secure. The disclosure also noted that similar signed-component weaknesses exist beyond Framework.

Framework ships signed UEFI shells vulnerable to Secure Boot bypass

Framework distributed signed diagnostic UEFI shell components on Linux laptops and desktops that could be abused to bypass Secure Boot. The issue affected roughly 200,000 Framework systems and stemmed from trusted signed components exposing dangerous low-level functionality.

Aug 1, 20224y ago

Eclypsium demonstrates signed UEFI shell Secure Boot bypass at DEF CON 30

Eclypsium researchers demonstrated that a signed UEFI shell containing the 'mm' memory-modification command could be abused to disable Secure Boot checks and load arbitrary pre-boot code. The presentation showed that trusted signed firmware components can be turned into a persistent firmware-level backdoor.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.