Windows BitLocker exploit sparks messy feud between Microsoft and the researcher who exposed it

TL;DR AI
2 min readKey summary
A researcher disclosed YellowKey, a USB-based proof of concept that can bypass BitLocker on Windows 11 and expose encrypted drives.
Microsoft acknowledged the flaw as CVE-2026-45585 and issued mitigation guidance, but has not released a full patch yet.
The disclosure sparked a public dispute: the researcher accused Microsoft of ignoring reports and withholding bounty payouts, while Microsoft said the public release broke coordinated disclosure norms.
The issue raises immediate security concerns for BitLocker-protected data and broader questions about trust in vulnerability reporting and bug bounty programs.
