AMD is facing backlash after refusing to pay a $10,000 bug bounty to a security researcher who discovered a serious flaw in its Auto Updater software.
Although AMD fixed the problem after 124 days, the company said the issue did not qualify for a reward under its bug bounty rules.
The vulnerability could have allowed attackers to intercept software updates and replace them with malicious files, potentially giving them control over a victim’s system.
The researcher reported the issue through AMD’s bug bounty program and expected compensation due to the bug’s severity. However, AMD rejected the payout, saying this type of attack was listed as out of scope in its policy.