AMD changes rules, denies researcher $10,000 bounty after taking 124 days to patch security flaw

https://www.techspot.com/images2/news/ts3_thumbs/2026/06/2026-06-12-ts3_thumbs-f3c.jpg

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

WTF?! AMD has patched a remote code execution vulnerability in its auto-updater software, but there's a lot more to this story. The company is facing a slew of criticism over how it handled the researcher who reported it. Team Red first dismissed the bug as "out of scope," then asked him to stay quiet, then changed its rules after the fact to make that silence a requirement.

The vulnerability was discovered by security researcher MrBruh after an AMD updater console window kept appearing on his new gaming PC.

Decompiling the software revealed that while AMD's updater pulled its update list over HTTPS, the executable download links themselves used plain HTTP. Worse still, the updater apparently performed no certificate validation or real signature check before running the downloaded file.

That vulnerability could allow a...

Copyright of this story solely belongs to techspot.com. To see the full text click HERE