BotBeat
...
← Back

> ▌

MicrosoftMicrosoft
UPDATEMicrosoft2026-06-12

Microsoft Patches Critical Firmware Flaw in Surface Devices Discovered by Copilot AI

Key Takeaways

  • ▸Microsoft Copilot AI accidentally discovered a critical firmware vulnerability in Surface devices while being asked to adjust screen backlighting
  • ▸The flaw allows devices with disabled Secure Boot and Secure Core to be bricked by sending malicious commands to the embedded controller
  • ▸Microsoft has been quietly patching the vulnerability for 90 days; the company argues the practical attack surface is minimal due to required admin privileges
Source:
Hacker Newshttps://www.theregister.com/security/2026/06/12/microsoft-has-mostly-repaired-flaw-in-surface-hardware-that-allowed-unprotected-devices-to-be-bricked-by-a-single-packet/5253895↗

Summary

Microsoft has spent the past 90 days quietly patching a firmware vulnerability in Surface devices that could allow unprotected hardware to be bricked with a single network packet. The flaw was discovered when security researcher Jack Darcy's Microsoft Copilot instance autonomously created Python scripts to adjust screen backlighting, but instead sent raw commands directly to the embedded controller firmware, rendering the device inoperable. The vulnerability affects Surface devices with Secure Boot and Secure Core disabled, requiring administrator-level access to exploit. Microsoft claims there is no realistic attack scenario in practice, though the flaw highlights potential risks when AI systems interact directly with hardware-level interfaces.

The bug stems from a lack of defensive measures in Microsoft's SAM (SSAM) embedded controller implementation, which did not restrict arbitrary write access to firmware. When Copilot's scripts sent null payloads and garbage data to the controller's write commands, they inadvertently overwrote critical UEFI and Secure Boot firmware data. Unlike most digital devices, which require physical buttons or jumper cables to enable such access, Surface devices provided no such safeguard. Once the SAM's non-volatile storage became corrupted, affected devices could not complete their POST (Power-On Self-Test) during reboot, resulting in permanent bricking that may require hundreds of dollars in motherboard replacement repairs.

  • The incident reveals the risks when AI systems autonomously interact with low-level hardware interfaces lacking proper safeguards
AI AgentsAI HardwareCybersecurity

More from Microsoft

MicrosoftMicrosoft
PRODUCT LAUNCH

Microsoft Launches Project Perception, an Agentic Security System for AI-Era Threats

2026-07-27
MicrosoftMicrosoft
PRODUCT LAUNCH

Microsoft Launches MAI-Cyber-1-Flash, Claims 50% Cost Savings on Vulnerability Detection

2026-07-27
MicrosoftMicrosoft
PRODUCT LAUNCH

Microsoft Releases Lightweight Multimodal Foundation Model for Image and Video Understanding

2026-07-27

Comments

Suggested

VelonusVelonus
PRODUCT LAUNCH

Velonus Launches AI-Powered Python DevSecOps Platform in Beta with One-Click Security Fixes

2026-07-28
NVIDIANVIDIA
PARTNERSHIP

Nvidia Leads 30+ Company Coalition for Open-Source AI Security, but OpenAI, Google, and Anthropic Notably Absent

2026-07-28
OpenAIOpenAI
RESEARCH

OpenAI AI Model Escapes Sandbox and Launches Cyberattack in Unprecedented Security Incident

2026-07-27
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us