Skip to content

Framework Laptop 13 — BIOS & Drivers

Subscribe to release notifications to get an email when new BIOS or driver updates are published for your Framework Laptop 13.

You can check your current BIOS version before installing an update.


AMD Ryzen™ AI 300 Series

4.02
Released 2026-06-11 · 19.8 MB
Stable
Latest
Highlights
  • Added support for Framework Laptop 13 Pro features — enabled compatibility for the haptic touchpad, touch panel, and 74W battery
  • Updated audio verb table to support new speakers in the Framework Laptop 13 Pro chassis
  • Added current battery level indicator to the BIOS Setup menu
  • Optimized widescreen rendering layout in the BIOS Setup menu
  • Standardized and corrected naming of various BIOS options
  • Updated PMF settings to support the updated 74Wh battery
  • Added Board ID support for new side LEDs
  • Fixed issue allowing the system to flash a BIOS intended for a different hardware platform
  • Fixed bug where iGPU Memory Size would fail to stay at 1/4 of total system memory after loading optimal defaults
  • Fixed issue where the system would fail to automatically power on upon connecting an AC adapter
  • Fixed bug where Chassis Intrusion Detection failed to revert to Disabled when supervisor password was cleared due to TPM availability changes
  • Resolved issue where Windows would unexpectedly enter Automatic Repair after changing TPM Availability to Hidden
  • Resolved issue where PMF power slider value would mismatch actual CPU performance after reboot
  • Resolved cosmetic issue with BIOS icon malformation
  • Fixed an issue where the Battery Extender status was reported incorrectly following a reboot, hibernation, or shutdown after the timer had expired.
Installation instructions

Intel® Core™ Ultra Series 1

3.06
Released 2026-04-13 · 15.6 MB
Stable
Latest
Highlights
  • Update Microcode to 0x24
  • Added Framework's dbx key and updated the default CA of Windows Secure Boot.
  • Fixed an issue where hardware encryption on OPAL drives could cause a missing boot drive on subsequent reboots.
  • Introduced Battery Charge Limiting status functionality.
  • Introduced the Framework EC device.
Installation instructions

AMD Ryzen™ 7040 Series

3.20
Released 2026-07-06 · 17.5 MB
Stable
Latest
Highlights
  • Added support for Framework Laptop 13 Pro features - Enabled compatibility for the haptic touchpad, touch panel, and 75W battery.
  • Updated the audio verb table to support the new speakers in the Framework Laptop 13 Pro chassis.
  • Updated AMD PhoenixPI-FP8-FP7_1.2.0.0f.
  • Fixed an issue where the system was unable to boot from partially locked self-encrypting drives (SEDs)
  • Fixed an issue where the Battery Extender status was reported incorrectly following a reboot, hibernation, or shutdown after the timer had expired.
  • Fixed an issue where the system boots with blackscreen when plugged Dell U2725QE monitor with mouse.
  • Supported 16bits postcode.
  • Fixed an issue where system audio volume was lower on 3.19 beta.
  • Security Fix: CVE-2025-54502 - Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution. (CVSS N/A)
  • Security Fix: CVE-2025-29949 - Insufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could allow an attacker to write out-of-bounds to corrupt Secure DRAM potentially resulting in denial of service. (CVSS N/A)
  • Security Fix: CVE-2025-0040 - Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow an attacker with physical access to read or overwrite the contents of cross-chip debug (XCD) registers potentially resulting in loss of data integrity or confidentiality. (CVSS N/A)
  • Security Fix: CVE-2024-36355 - Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify execution flow for S3 (sleep) wake up, potentially resulting in arbitrary code execution. (CVSS N/A)
  • Security Fix: CVE-2024-36310 - Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds read or write to SMRAM potentially resulting in loss of confidentiality or integrity. (CVSS N/A)
Installation instructions

13th Gen Intel® Core™

3.17
Released 2026-06-22 · 13.6 MB
Stable
Latest
Highlights
  • You can downgrade to a previous BIOS version from 3.17
  • Security fix: CVE-2025-32008 — Out-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) Standard Manageability within Ring 3 (CVSS 8.6)
  • Security fix: CVE-2025-20080 — Null pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0 (CVSS 6.8)
  • Security fix: CVE-2025-27708 — Out-of-bounds read in the firmware for some Intel(R) Converged Security and Management Engine (CSME) Firmware (FW) within Ring 0 (CVSS 4.1)
  • Security fix: CVE-2025-31648 — Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. (CVSS 3.9)
  • Updated MCU 0x6134.
  • Updated CSME 16.1.40.2765v3.
  • Added support for Framework Laptop 13 Pro features - Enabled compatibility for the haptic touchpad, touch panel, and 74W battery. Updated the audio verb table to support the new speakers in the Framework Laptop 13 Pro chassis.
  • Enhanced the Power On AC behavior, allowing the feature to work correctly without requiring the system to boot into the Operating System at least once for initialization.
  • Fixed an issue where the Battery Extender status was reported incorrectly following a reboot, hibernation, or shutdown after the timer had expired.
Installation instructions

12th Gen Intel® Core™

3.20
Released 2026-07-06
Stable
Latest
Highlights
  • Updated CSME to 16.1.40.2765v3 Corporate.
  • Update Microcode to 0x43B.
  • Added support for Framework Laptop 13 Pro features - Enabled compatibility for the haptic touchpad, touch panel, and 74W battery.
  • Fixed an issue where the system was unable to boot from partially locked self-encrypting drives (SEDs)
  • Fixed an issue where the Battery Extender status was reported incorrectly following a reboot, hibernation, or shutdown after the timer had expired.
  • Enhanced the Power On AC behavior, allowing the feature to work correctly without requiring the system to boot into the Operating System at least once for initialization.
  • Security Fix: CVE-2025-32008 - Out-of-bounds write in the firmware for the Intel® AMT and Intel® Standard Manageability within Ring 3: User Applications may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts. (CVSS 8.6)
  • Security Fix: CVE-2024-24853 - Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel® Processor may allow a privileged user to potentially enable escalation of privilege via local access. (CVSS 7.2)
  • Security Fix: CVE-2025-20080 - Null pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0: Kernel may allow a denial of service. Network adversary with an unauthenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. (CVSS 6.8)
  • Security Fix: CVE-2025-27708 - Out-of-bounds read in the firmware for some Intel(R) Converged Security and Management Engine (CSME) Firmware (FW) within Ring 0: Kernel may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. (CVSS 4.1)
  • Security Fix: CVE-2025-31648 - Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts. (CVSS 3.9)
Installation instructions

11th Gen Intel® Core™

3.25
Released 2026-07-06
Maintenance
Latest
Highlights
  • Updated Intel SIC to 8063.00.
  • Updated CSME to 15.0.55.2751v6 Corporate.
  • Update Microcode to 0xBE.
  • Added support for Framework Laptop 13 Pro features - Enabled compatibility for the haptic touchpad, touch panel, and 74W battery.
  • Fixed an issue where the system was unable to boot from partially locked self-encrypting drives (SEDs)
  • Fixed an issue where the Battery Extender status was reported incorrectly following a reboot, hibernation, or shutdown after the timer had expired.
  • Enhanced the Power On AC behavior, allowing the feature to work correctly without requiring the system to boot into the Operating System at least once for initialization.
  • Secure Fix: CVE-2025-32008 - Out-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) Standard Manageability within Ring 3: User Applications may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts. (CVSS 8.6)
  • Secure Fix: CVE-2025-20080 - Null pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0: Kernel may allow a denial of service. Network adversary with an unauthenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. (CVSS 6.8)
  • Secure Fix: CVE-2025-27708 - Out-of-bounds read in the firmware for some Intel(R) Converged Security and Management Engine (CSME) Firmware (FW) within Ring 0: Kernel may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. (CVSS 4.1)
  • Secure Fix: CVE-2025-31648 - Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts. (CVSS 3.9)
Installation instructions