← All news

vulnerability

Copilot Bricked a Surface and Exposed a Hidden Firmware Flaw

2026-06-12

Here is a story with an unlikely protagonist. Australian security researcher Jack Darcy asked Microsoft Copilot to help adjust the screen backlight on his Surface. Copilot wrote a Python script, ran it, escalated through four increasingly aggressive variants, and bricked the laptop. Along the way, it stumbled onto a firmware flaw that had been sitting in Surface hardware for years.

What Copilot actually broke

The fault lives in the Surface System Aggregator Module, the embedded controller that handles low level hardware functions. Darcy found the controller accepts arbitrary write commands with no safety check. No jumper, no button hold, nothing. Worse, the command IDs for reads and writes are interleaved in the same numbering space, so any attempt to probe what is available has a coin flip chance of firing off a destructive write.

Copilot's script blindly iterated through those commands with null payloads and overwrote the UEFI and Secure Boot firmware. The machine kept running until reboot, at which point the controller tried to reload from corrupted storage, failed POST, and that was that. No USB recovery, no BIOS access, no factory reset. New motherboard time.

Microsoft's quiet 90-day fix

Microsoft has spent the last three months pushing fixes through Windows Update and says most affected devices are now patched. The company is keen to point out the attack is not particularly practical. You need administrator privileges and Secure Boot already disabled, so a managed corporate fleet is largely fine. The flaw did not meet the bar for a CVE.

Still exposed:

  • People running Linux on Surface hardware
  • Gamers who turn Secure Boot off
  • Anyone using custom drivers
  • Anyone whose machine has not pulled the update yet

Darcy reckons it affects Surface Laptops 3 to 6 and Surface Book 1 to 3. Surface Go appears to be spared.

Rust to the rescue

The quieter detail buried in Microsoft's response is that the company is rewriting the Surface embedded controller and UEFI core in Rust, under projects called Secure EC and Project Patina. That is a tacit admission that the existing C based firmware stack has aged badly, and that decades of accumulated assumptions about what userspace can and cannot reach are no longer holding up.

The agentic AI bit

There is also something genuinely odd about an AI assistant being the one to find this. Darcy did not set out to probe firmware. He wanted to dim his screen. Copilot, given enough rope, wrote itself into destroying the host machine. Whatever you think about agentic AI running scripts on your behalf, this is the kind of story that should give anyone with admin rights and a curious chatbot reason to pause.

Copilot Bricked a Surface and Exposed a Hidden Firmware Flaw | RiskSense