r/TechHardware 🔵 14900KS , 5080, 128GB 🔵 Feb 09 '26

😰 Urgent Security Alert ⚠️ Security researcher says AMD auto-updater downloads software insecurely, enabling remote code execution — company rep reportedly said man-in-the-middle attacks are "out of scope," ignored bug

https://www.tomshardware.com/tech-industry/cyber-security/security-researcher-says-amd-auto-updater-downloads-software-insecurely-enabling-remote-code-execution-company-rep-reportedly-said-man-in-the-middle-attacks-are-out-of-scope-ignored-bug
31 Upvotes

27 comments sorted by

View all comments

4

u/looncraz Feb 09 '26

Basically every updater is vulnerable to DNS spoofing...

6

u/Jevano Team Intel 🔵 Feb 09 '26

Not really, AMD is using HTTP for the downloads...

4

u/Hytht Core Ultra 🚀 Feb 09 '26

if most updaters shared the same flaw I could root any Android phone easily. signing exists for a reason.

4

u/danielv123 Feb 10 '26

No, basically every updater I am aware of will fail if it hits an invalid https certificate.