TGViewer
cKure Red cKure Red @ckured · 2.77K subscribers
Post #604 1.58K
💧🌊 Hydroph0bia (CVE-2025-4275) - a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O.

Secure Boot bypass for laptops, embedded and medical devices, and car ECUs: technical details and exploit. Security researcher Nikolaj Schlej shared yesterday a new and quite effective (even trivial) way to bypass Secure Boot in Insyde H20 UEFI BIOS. The vulnerability, CVE-2025-4275, was named Hydroph0bia by the author. Most ARM-based laptops from Acer, HP, Lenovo, Huawei, Samsung, and Dell use this BIOS and are therefore affected. This product is also ported to multiple systems for IoT, SCADA, and critical infrastructure. Insyde H20 continuously presents its solutions for communication devices, robotics, and manufacturing equipment. Car components, as well as other areas in digital mobility (aviation, maritime, and railroad), also use Insyde H20 Secure Boot as part of ARM-based and other UEFI-compatible systems. So, check your SBOMs and make sure your product is not affected.


https://coderush.me/hydroph0bia-part1/

https://coderush.me/hydroph0bia-part2/
More from @ckured
  1. Oct 3, 2026Update: Archivegenocide has now crossed 200,000 videos & images, which is almost triple wh…
  2. Sep 29, 2026📱 Telegram OSINT tactics
  3. Sep 26, 2026☁️ Italian firm Dataflow Security, founded in 2019 by young hacker Luca Todesco, develops…
  4. Sep 23, 2026Alleged Google Pixel 10 Zero Day at 2.5K USD only as chain included some n-days. An intere…
  5. Sep 18, 2026AliExpress spyware caught using side channel attack to compromise hardware.
  6. Sep 17, 2026😒 Claude Code was used to make missile guidance system for 9 months by Houthis using mult…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →