AMD Gaslights Security Researcher, Changes Rules Retroactively

AMD faced backlash for dismissing and delaying a fix for a remote code execution vulnerability in its Ryzen Master autoupdate software, while retroactively changing its bug bounty policy to penalize the researcher who responsibly disclosed the issue. The company’s poor communication, misrepresented patch security, and failure to inform users about necessary uninstall steps led to widespread criticism and mistrust from the security community.

AMD recently faced criticism for its handling of a remote code execution vulnerability discovered in its Ryzen Master autoupdate software by security researcher Mr. Bruh. The vulnerability allowed man-in-the-middle attacks due to the use of insecure HTTP links and lack of certificate validation in the autoupdate process. Mr. Bruh responsibly disclosed the issue to AMD in early February, but AMD initially dismissed the report as “out of scope” of its bug bounty program, effectively ignoring the security risk for months.

After Mr. Bruh publicly shared the vulnerability on Hacker News, drawing user attention and criticism towards AMD’s lack of response, the company backtracked. AMD claimed the report was still under review by a different internal team, despite previously closing it. Furthermore, AMD accused Mr. Bruh of violating its bug bounty terms by posting about the vulnerability, even though the report was deemed out of scope and he was no longer part of the program. AMD then retroactively changed its bug bounty policy to make such disclosures a violation, which many viewed as an attempt to gaslight and discredit the researcher.

AMD finally released a patch after 124 days, exceeding the industry standard of 90 days, but the fix was misrepresented. While AMD claimed the update communications were secured with HTTPS and that updates underwent signature verification, Mr. Bruh found that only a CRC32 checksum was used, which is not cryptographically secure. Additionally, due to a separate URL redirection bug in the updater, users need to completely uninstall Ryzen Master before installing the patched version—a critical step AMD failed to inform its users about, potentially leaving many vulnerable.

The entire situation highlights poor communication and transparency from AMD’s side. The company’s initial dismissal, delayed response, retroactive policy changes, and lack of clear user guidance on patching created confusion and mistrust. This case underscores the importance of companies engaging constructively with security researchers, adhering to industry standards for vulnerability disclosure, and prioritizing user safety over PR damage control.

In conclusion, while vulnerabilities are common and not inherently scandalous, AMD’s handling of this issue has been widely criticized as manipulative and irresponsible. Security researchers like Mr. Bruh play a vital role in protecting users, and companies must respect their work by providing timely fixes, clear communication, and fair treatment. Users of Ryzen Master are advised to uninstall the current version and install the latest patched release from AMD’s website to ensure their systems are secure.