1 of 1
Story summary
- AMD patched its auto-updater on June 9, 2026, switching driver downloads to HTTPS and issuing CVE-2026-40677 (CVSS 7.7).
- Paul LaRosa reported on February 6, 2026 that the updater fetched drivers via HTTP, enabling a man-in-the-middle attack.
- AMD said report was out of scope, closed it, asked LaRosa to delete his blog post, and refused a $10,000 bounty.
- The June 9 fix uses CRC32 checksums and has a redirection bug, so researchers advise a manual reinstall.
