PulseAugur
EN
LIVE 13:02:32

AMD denies bug bounty for critical auto-updater flaw after 124-day fix

AMD has denied a security researcher a $10,000 bug bounty for discovering a critical vulnerability in its auto-updater software. The researcher, Paul, reported the flaw in February, which could have allowed for remote code execution via a man-in-the-middle attack. Despite AMD's request to temporarily take down his blog post detailing the issue, the company took 124 days to implement a fix and did not offer any bounty payment, citing program policy limitations. AI

IMPACT This incident highlights potential issues in how tech companies handle bug reporting and bounty programs, which could affect researcher trust and software security practices.

RANK_REASON This is a story about a company's internal policy and a dispute over a bug bounty, not a new product release or significant industry-wide event.

Read on Tom's Hardware →

AI-generated summary · Google Gemini · from 2 sources. How we write summaries →

AMD denies bug bounty for critical auto-updater flaw after 124-day fix

COVERAGE [2]

  1. Tom's Hardware TIER_1 English(EN) · Bruno Ferreira ·

    AMD denies researcher a $10,000 bug bounty after fixing critical auto-updater vulnerability — security flaw took 124 days to patch

    AMD took over four months to fix a critical security bug in its autoupdater, and the security researcher didn't see a dime for his efforts

  2. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    AMD denies researcher a $10,000 bug bounty after fixing critical auto-updater vulnerability — security flaw took 124 days to patch AMD took over four months to

    AMD denies researcher a $10,000 bug bounty after fixing critical auto-updater vulnerability — security flaw took 124 days to patch AMD took over four months to fix a critical security bug in its autoupdater, and the security researcher didn't see a dime for his efforts https://ww…