A vulnerability in HP ThinPro 8 and 9 operating systems allows attackers with physical access to bypass TPM-backed full-disk encryption and recover the key securing the device's root partition. The zero-day vulnerability remained unpatched when security researcher Darren McDonald disclosed it on August 8, as reported by Cyber Insider.The flaw, discovered by McDonald in early 2026, lies in how the Trusted Platform Module (TPM) verifies boot chain measurements before releasing the LUKS encryption key. HP ThinPro's TPM policy includes measurements for the BIOS, option ROMs, and GRUB bootloader, but omits measurements for the Linux kernel and initramfs. This gap allows an attacker with physical access to modify the initramfs, specifically a script that copies the disk encryption key to the unencrypted boot partition. After modifying the script and reinstalling the storage drive, the TPM releases the legitimate key, allowing the system to boot normally. The attacker can then retrieve the raw LUKS key from the boot partition and decrypt the protected data offline.This vulnerability affects HP t530 and t540 devices running ThinPro 8 and 9. Organizations using ThinPro should not rely solely on full-disk encryption for data protection if devices leave their control. Recommendations include enabling Secure Boot, setting a BIOS password, and securely destroying or erasing storage media for retired devices.Source: Cyber Insider
Encryption
HP ThinPro vulnerability allows physical attackers to bypass disk encryption
(Photo by Justin Sullivan/Getty Images)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
