Millions of Dell PCs with Broadcom Chips Open to Attack
WORLDWIDE, AUG 5 – Researchers found five critical firmware flaws in Broadcom chips affecting business-focused Dell laptops that allow data theft and persistent backdoors, with patches released since March 2025.
- Cisco Talos researchers found five vulnerabilities in Broadcom BCM5820X chips affecting more than 100 Dell laptop models, risking tens of millions of devices.
- The flaws reside in Dell ControlVault3’s firmware, which affects the Dell ControlVault hardware security component, with vulnerabilities in ControlVault3+ firmware as well.
- Demonstrating the exploit, Philippe Laulheret showed how CVE-2025-24919’s unsafe-deserialization in ControlVault’s Windows APIs allows backdoor implants and login bypasses.
- To date, Dell said it addressed the flaw quickly and transparently under its Vulnerability Response Policy, with no evidence of in-the-wild exploitation found.
- Amid the findings, Cisco highlighted importance of security from hardware to AI models, teaming up with Hugging Face to address AI supply chain risks.
18 Articles
18 Articles
Cisco's cybersecurity intelligence division, Cisco Talos, has discovered security flaws that affect over a hundred models of Dell laptops equipped with Broadcom chips, which focus on both the 'firmware' ControlVault3 and its Windows APIs, putting at risk 'tens of millions' of devices on a global scale.
ReVault Flaws Let Hackers Bypass Windows Login On Dell Laptops - Cybernoz - Cybersecurity News
ControlVault3 firmware vulnerabilities impacting over 100 Dell laptop models can allow attackers to bypass Windows login and install malware that persists across system reinstalls. Dell ControlVault is a hardware-based security solution that stores passwords, biometric data, and security codes within firmware on a dedicated daughterboard, known as the Unified Security Hub (USH). The five vulnerabilities, reported by Cisco’s Talos security divisi…
Coverage Details
Bias Distribution
- 75% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium