Switch language한국어
Back to the list

Windows BitLocker exploit sparks messy feud between Microsoft and the researcher who exposed it

TL;DR AI

Key summary

2 min read
  1. A researcher disclosed YellowKey, a USB-based proof of concept that can bypass BitLocker on Windows 11 and expose encrypted drives.

  2. Microsoft acknowledged the flaw as CVE-2026-45585 and issued mitigation guidance, but has not released a full patch yet.

  3. The disclosure sparked a public dispute: the researcher accused Microsoft of ignoring reports and withholding bounty payouts, while Microsoft said the public release broke coordinated disclosure norms.

  4. The issue raises immediate security concerns for BitLocker-protected data and broader questions about trust in vulnerability reporting and bug bounty programs.

Read the original