logo

Secure Boot Bypass on NXP i.MX

ID: f7b4d146-2d3f-530b-85f9-518cbc660771

STIX ID: report--f7b4d146-2d3f-530b-85f9-518cbc660771

Feed Name: NCC Research

Threat Score
55/100

Date Published: 2026-05-15

Date Updated: 2026-08-01

...
...

This report details a mitigated but serious secure-boot bypass in NXP i.MX devices running HABv4 versions older than 4.3.7, where maliciously modified DCD or CSF sections can execute ROM commands that alter a second-stage bootloader in RAM before authentication is verified; the author demonstrates PoC techniques, documents the vendor and U-Boot software mitigations (and their release timeline), and highlights concerns about potentially unpatched field devices due to supply-chain and update-delivery complexities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.