BotBeat
...
← Back

> ▌

MicrosoftMicrosoft
UPDATEMicrosoft2026-06-12

Microsoft Patches Critical Firmware Flaw in Surface Devices Discovered by Copilot AI

Key Takeaways

  • ▸Microsoft Copilot AI accidentally discovered a critical firmware vulnerability in Surface devices while being asked to adjust screen backlighting
  • ▸The flaw allows devices with disabled Secure Boot and Secure Core to be bricked by sending malicious commands to the embedded controller
  • ▸Microsoft has been quietly patching the vulnerability for 90 days; the company argues the practical attack surface is minimal due to required admin privileges
Source:
Hacker Newshttps://www.theregister.com/security/2026/06/12/microsoft-has-mostly-repaired-flaw-in-surface-hardware-that-allowed-unprotected-devices-to-be-bricked-by-a-single-packet/5253895↗

Summary

Microsoft has spent the past 90 days quietly patching a firmware vulnerability in Surface devices that could allow unprotected hardware to be bricked with a single network packet. The flaw was discovered when security researcher Jack Darcy's Microsoft Copilot instance autonomously created Python scripts to adjust screen backlighting, but instead sent raw commands directly to the embedded controller firmware, rendering the device inoperable. The vulnerability affects Surface devices with Secure Boot and Secure Core disabled, requiring administrator-level access to exploit. Microsoft claims there is no realistic attack scenario in practice, though the flaw highlights potential risks when AI systems interact directly with hardware-level interfaces.

The bug stems from a lack of defensive measures in Microsoft's SAM (SSAM) embedded controller implementation, which did not restrict arbitrary write access to firmware. When Copilot's scripts sent null payloads and garbage data to the controller's write commands, they inadvertently overwrote critical UEFI and Secure Boot firmware data. Unlike most digital devices, which require physical buttons or jumper cables to enable such access, Surface devices provided no such safeguard. Once the SAM's non-volatile storage became corrupted, affected devices could not complete their POST (Power-On Self-Test) during reboot, resulting in permanent bricking that may require hundreds of dollars in motherboard replacement repairs.

  • The incident reveals the risks when AI systems autonomously interact with low-level hardware interfaces lacking proper safeguards
AI AgentsAI HardwareCybersecurity

More from Microsoft

MicrosoftMicrosoft
INDUSTRY REPORT

Digital Sovereignty Becomes an Imperative as the US Reads Dutch Emails

2026-06-12
MicrosoftMicrosoft
INDUSTRY REPORT

Microsoft Warns Big Tech That Gen Z's AI Backlash Signals Need for Accountability

2026-06-11
MicrosoftMicrosoft
RESEARCH

Research Reveals 'Fugue Lock'—LLMs Enter Erratic States When Over-Constrained

2026-06-10

Comments

Suggested

Artificial AnalysisArtificial Analysis
PRODUCT LAUNCH

NVIDIA Announces AgentPerf: First Agentic AI Infrastructure Benchmark

2026-06-12
Unnamed AI Defense Startup (Gavin Kliger, Luke Farritor, Jack Stein)Unnamed AI Defense Startup (Gavin Kliger, Luke Farritor, Jack Stein)
FUNDING & BUSINESS

Ex-DOGE Engineers Raise $130 Million for AI-Powered National Security Startup

2026-06-12
AnthropicAnthropic
RESEARCH

The 98% Problem: Harness Engineering Emerges as the Real Differentiator for AI Agents

2026-06-12
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us