PC

AMD Accused of Dodging $10K Bug Bounty Payout

Gamer24H Editorial Team June 12, 2026 3 min read 43 views

Security analyst MrBruh uncovered that AMD’s updater downloaded files without proper verification, allowing a malicious actor to hijack a machine. When he reported the issue, AMD initially dismissed the claim as “out of scope,” denying him a $10,000 bounty. They then pressured him into silence, secretly altered the bounty program’s terms to justify their stance, and delayed a fix for 124 days— a period during which the vulnerability remained only partially resolved.

Analysis: AMD’s protracted response and opaque policy changes highlight a growing tension between corporate security practices and the responsible‑disclosure community, potentially eroding trust among developers and users alike.

Just days before, AMD faced backlash for refusing warranty service to a customer with a faulty processor, underscoring a pattern of inadequate customer support and reactive security measures.

The core issue lay in the installer’s failure to validate digital signatures or certificates before executing downloaded files. This oversight opened the door to a severe cyber‑attack: an intruder on the same network could replace AMD’s official file with malware, and because the installer runs with elevated system privileges, the attacker could execute code remotely and seize full control of the affected computer.

After discovering the flaw on January 27, MrBruh promptly filed an official report with AMD’s bug‑bounty program on February 6. The company’s response was to close the case, labeling the defect as “out of scope” and citing its impact on optional tools and the need for local‑network interception.

When the researcher finally received the promised $10,000 bounty, the reward was unexpectedly withheld. Only after 124 days of back‑and‑forth did the restriction period end on June 9, even though the flaw had already been catalogued in security databases with a high risk rating.

Seeing no resolution in sight, MrBruh posted his findings online. The story quickly went viral across tech forums, prompting AMD’s security team to re‑engage and inform him that the issue was still under review. The company requested that he remove the post while they worked on a patch, citing that public disclosure violated the terms of their bug‑bounty program.

AMD eventually issued an official statement acknowledging the vulnerability and crediting MrBruh for his investigative work. The communiqué confirmed that the flaw had been mitigated and listed the updated, secure versions of its software now available to the public. However, the patch still raises concerns within the security community. AMD assured the researcher that all update communications would use secure channels and that files would be signed, but upon review, MrBruh found that the system only performs a basic data check, which does not constitute genuine cryptographic signing.

News Source: Tarreo

Community

Comments

Be the first to comment.

Leave a Comment

Your email address will not be published. Required fields are marked *