A disclosed zero-day in HP ThinPro 8 and 9 allows an attacker with physical access to bypass TPM-backed full-disk encryption and recover the LUKS key protecting the root partition on affected HP thin clients. The weakness stems from incomplete TPM boot measurements: the sealed key is reportedly tied to PCRs covering the BIOS, option ROMs, and parts of the boot chain, but not the Linux kernel or initramfs. That gap lets an attacker alter an unencrypted initramfs to capture the legitimate disk-encryption key without changing the PCR values checked before key release.
The issue was confirmed on HP t530 and HP t540 devices running ThinPro 8.1.0 build 22 and ThinPro 9.0.0 build 15. After modifying the boot components, an attacker can reinstall the drive, allow the device to boot normally, and then retrieve the raw key from the unencrypted boot partition for offline decryption, exposing the encrypted root filesystem and data such as device configuration, certificate stores, stored credentials, and password hashes. Researcher Darren McDonald reported the flaw to HP PSIRT, and HP reportedly said a fix was in quality assurance, but no CVE, security bulletin, or patch was available at disclosure time.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
McDonald publicly disclosed the HP ThinPro 8 and 9 vulnerability on August 8 while it was still unpatched. At disclosure time, no CVE, security bulletin, or shipped patch was available.
The researcher reported the boot-chain weakness affecting HP ThinPro full-disk encryption to HP PSIRT. HP later indicated that a fix was undergoing quality assurance.
Security researcher Darren McDonald discovered a vulnerability in HP ThinPro 8 and 9 in early 2026 that allows a physical attacker to recover the LUKS disk-encryption key by modifying the unmeasured initramfs in the boot chain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.