P
Back to articles
News2 min read

AMD denies researcher a $10,000 bug bounty after fixing critical auto-updater vulnerability — security flaw took 124 days to patch

AMD refused to pay a $10,000 bug bounty for a critical RCE vulnerability in its auto-updater, taking 124 days to patch a simple HTTP-to-HTTPS fix.

Source: Tom's Hardware
AMD denies researcher a $10,000 bug bounty after fixing critical auto-updater vulnerability — security flaw took 124 days to patch

AMD Denies $10,000 Bug Bounty After 124-Day Patch Delay for Critical Auto-Updater Flaw

AMD has refused to pay a $10,000 bug bounty to a security researcher who discovered a critical remote code execution (RCE) vulnerability in the company's auto-updater software — despite the flaw taking 124 days to patch and affecting multiple AMD tools beyond the initially reported Ryzen Master utility.

The Vulnerability: A Simple But Dangerous Flaw

The vulnerability, discovered by a researcher identified as "Paul," was remarkably straightforward: AMD's auto-updater was downloading updates over unencrypted HTTP connections instead of HTTPS. This created a classic man-in-the-middle (MITM) attack vector where an attacker on the same network could intercept the update process and inject malicious code, achieving remote code execution on the target system.

The fix was equally simple — changing "http" to "https" in the code — yet AMD took over four months to deploy it across all affected products.

Timeline of Events

Paul initially reported the vulnerability to AMD's bug bounty program in February 2025, expecting both a fix and the standard $10,000 payout for an RCE-class bug. AMD's response was surprising: the company rejected the bounty claim, stating that MITM attacks were not covered by their bug bounty program's policy.

Despite denying the bounty, AMD asked Paul to temporarily remove his blog post describing the vulnerability. The company promised to issue a CVE, fix the software, and credit Paul for the discovery — but explicitly stated a bounty payment was "out of the question."

Paul agreed to the 100-day embargo period (beyond the industry-standard 90 days), but AMD repeatedly requested extensions. The company cited additional affected tools beyond Ryzen Master and customer requests for more time once fixes were available. The patch finally arrived on June 9, 2025 — 124 days after the initial report.

Broader Implications for Bug Bounty Programs

This incident raises serious questions about the effectiveness and good faith of corporate bug bounty programs. When companies can retroactively exclude vulnerability classes from bounty eligibility — especially after a researcher has already invested time in discovery and responsible disclosure — it undermines the entire security research ecosystem.

The case echoes similar controversies, including Microsoft's handling of the Nightmare-Eclipse vulnerability, where researchers faced comparable challenges in receiving recognition and compensation for critical findings.

Current Status

Users who download the latest version of AMD's software suite should now receive the patched updater with HTTPS enforcement. However, the researcher reportedly never received any financial compensation for a vulnerability that AMD itself acknowledged required 124 days to fully remediate across its product line.

The episode serves as a cautionary tale for security researchers considering participation in vendor bug bounty programs, and highlights the need for clearer, enforceable standards around vulnerability disclosure and researcher compensation.

Related Articles

Frontier Airlines site leaks all personal info with just a glance at a boarding pass, researcher claims — booking number and last name nets you every passenger's personal info, including address, passport, TSA PreCheck, and most credit card info
News4 min

Frontier Airlines site leaks all personal info with just a glance at a boarding pass, researcher claims — booking number and last name nets you every passenger's personal info, including address, passport, TSA PreCheck, and most credit card info

Security researcher Bob reveals Frontier Airlines exposed passenger passport data, credit card info, and TSA PreCheck numbers through a simple API flaw — just a boarding pass code and last name.

Hardware
Kaspersky finds malware hidden in Steam Wallpaper Engine that hijacks accounts to spread itself — dozens of malicious packages downloaded tens of thousands of times
News3 min

Kaspersky finds malware hidden in Steam Wallpaper Engine that hijacks accounts to spread itself — dozens of malicious packages downloaded tens of thousands of times

Kaspersky researchers uncover a months-long malware campaign exploiting Steam's Wallpaper Engine executable wallpaper feature, with dozens of malicious packages downloaded tens of thousands of times to deliver infostealers and ransomware.

Hardware
Chinese memory brands ditch Samsung and Micron for homegrown CXMT and YMTC silicon — Corsair, HP, and Dell are already adopting the China-produced DDR5 chips
News4 min

Chinese memory brands ditch Samsung and Micron for homegrown CXMT and YMTC silicon — Corsair, HP, and Dell are already adopting the China-produced DDR5 chips

Chinese memory brands Gloway and KingBank ditch Samsung and Micron for homegrown CXMT DDR5 chips, with Corsair, HP, and Dell already adopting the China-produced memory modules.

Hardware
AMD silently removes memory encryption from consumer Ryzen CPUs, leaving users unaware that they may be vulnerable — security feature vanishes after newer AGESA firmware, AMD engineers go radio silent when pressed about the change
News3 min

AMD silently removes memory encryption from consumer Ryzen CPUs, leaving users unaware that they may be vulnerable — security feature vanishes after newer AGESA firmware, AMD engineers go radio silent when pressed about the change

AMD quietly disabled Transparent Secure Memory Encryption (TSME) on consumer Ryzen CPUs through AGESA 1.2.7.0 firmware updates. AMD engineers went silent when pressed for answers.

Hardware