A wide range of vulnerabilities affect millions of Dell laptops used by government organizations, cybersecurity professionals, and businesses worldwide.
See also: Dell says data leaked by hackers is fake

The vulnerabilities, collectively called “ ReVault ,” target the Broadcom BCM5820X security chip embedded in Dell’s ControlVault3 firmware , creating opportunities for attackers to steal passwords, biometric data, and maintain permanent access to compromised systems .
The vulnerabilities affect more than 100 different Dell laptop models, primarily from the Latitude and Precision that are widely deployed in sensitive environments. These devices are typically found in cybersecurity firms and government facilities, where enhanced security features such as smartcard authentication and NFC (near-field communication) are essential.
Dell ControlVault operates as a hardware-based security solution that provides a secure repository that stores passwords, biometric templates, and security codes within the firmware. The system operates on a separate board called the Unified Security Hub (USH), which connects various security, including fingerprint readers, smart card readers, and NFC devices.
Cisco Talos researchers identified five distinct vulnerabilities in ControlVault3 and ControlVault3+ systems:
– CVE-2025-24311: An out-of-bounds read vulnerability that allows information leakage.
– CVE-2025-25050: An out-of-bounds write vulnerability that allows code execution.
– CVE-2025-25215: An arbitrary memory free vulnerability.
– CVE-2025-24922: A stack-based buffer overflow that allows arbitrary code execution.
– CVE-2025-24919: A dangerous disassembly vulnerability in the Windows APIs of ControlVault.
See also: Dell confirms platform breach by World Leaks
All vulnerabilities received CVSS (Common Vulnerability Scoring System) scores above 8.0, classifying them as high-severity threats. The combination of these flaws creates particularly dangerous attacks that security experts warn could have long-term consequences.

The most concerning aspect of the ReVault vulnerabilities is their potential to create a permanent compromise that remains undetected even after a complete reinstall of Windows. According to the researchers, a non-administrative user can interact with the ControlVault firmware via Windows APIs to trigger arbitrary code execution, allowing attackers to extract cryptographic keys and permanently modify the firmware.
"This creates the risk of a so-called implant that could remain undetected in a laptop's ControlVault firmware and ultimately be used as a system rollback point in the event of a threat actor breach," the Talos team explained in their technical disclosure.
The persistent nature of these attacks represents a significant escalation in firmware-based threats, as the malicious code resides below the operating system level, where traditional antivirus solutions cannot detect or remove it.
In addition to remote exploitation, the vulnerabilities also allow for devastating physical attacks. Researchers have demonstrated that an attacker with brief physical access to a laptop can open the case and gain direct access to the USH board via USB using an adapter. This approach bypasses the need for system login credentials or knowledge of full disk encryption keys.
The researchers showed how the modified ControlVault firmware could be configured to accept any fingerprint for authentication, including non-human objects like vegetables. A video published by Cisco Talos shows a fresh onion successfully unlocking a compromised Dell laptop, highlighting the complete collapse of biometric security controls.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: US Department of Energy: Collaboration with NVIDIA & Dell for the new supercomputer
"If a system is configured to unlock with the user's fingerprint, it is also possible to modify the ControlVault firmware to accept any fingerprint instead of only allowing the legitimate user," the researchers noted.
