Microsoft Uses Security Copilot to Identify 20 Flaws in Open-Source Bootloaders

Microsoft found the vulnerabilities in the GRUB2, U-Boot, and Barebox bootloaders.

Advertisement
Written by Akash Dutta, Edited by David Delima | Updated: 2 April 2025 19:32 IST
Highlights
  • GRUB2 is the default bootloader for many Linux-based systems
  • U-boot and Barebox bootloaders are typically used in embedded systems
  • Microsoft discovered 11 security flaws in the GRUB2 bootloader

Bootloader maintainers have released security updates to fix the issues

Photo Credit: Microsoft

Microsoft Security Copilot, an artificial intelligence (AI) cybersecurity tool, was used to discover several previously unknown vulnerabilities in open-source bootloaders. The Redmond-based tech giant recently revealed a list of the security flaws discovered in three commonly used bootloaders. One of the bootloaders is the default for many Linux-based systems, while the other two are typically used for embedded systems and Internet of Things (IoT) devices. Notably, Microsoft has informed the bootloader maintainers about the exploits, and they have released security updates to fix them.

Microsoft Showcases Its AI System's Vulnerability Discovery Process

In a blog post, Microsoft detailed the discovery process and extent of risk with these vulnerabilities. The company used Security Copilot, an AI-powered security analysis tool that can assist in protecting organisations from threat actors as well as discovering security flaws. These vulnerabilities were detected in GRand Unified Bootloader (GRUB2), U-Boot, and Barebox, commonly used bootloaders for operating systems and devices.

Advertisement

GRUB2 is the default bootloader for many Linux-based systems, whereas U-Boot and Barebox are generally seen in embedded systems and IoT devices. Notably, a bootloader is a small program that runs before the operating system (OS) starts. It is responsible for loading the OS into memory and initiating the boot process.

By using AI, Microsoft Threat Intelligence discovered 11 vulnerabilities in GRUB2, including issues like integer overflows, buffer overflows, and a cryptographic side-channel flaw. These security flaws could allow threat actors to bypass the Unified Extensible Firmware Interface (UEFI) Secure Boot, which is designed to prevent unauthorised code from running during the boot process.

Advertisement

Security Copilot also discovered nine vulnerabilities in U-Boot and Barebox. These were primarily buffer overflows that affected file systems such as SquashFS, EXT4, CramFS, JFFS2, and symlinks. Notably, the threat actor would need to have physical access to the device to exploit these flaws, however, the security risk still exists.

In the case of GRUB2, Microsoft explained that the vulnerabilities could be exploited by attackers to install stealthy bootkits remotely. This is concerning, as such bootkits can persist even after reinstalling the operating system or replacing the hard drive.

Advertisement

The teams behind GRUB2, U-Boot, and Barebox have already released security updates in February to address these vulnerabilities. Users are advised to update their systems to the latest versions to protect themselves from potential cyberattacks.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Find X9 Ultra With 200-Megapixel Periscope Camera Launched Globally
  2. Poco M8s 5G Debuts Globally With 7,000mAh Battery: See Price, Features
  3. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
  4. Vivo Y600 Pro Could Launch Soon With This MediaTek Dimensity Chip
  5. Redmi K90 Max Debuts With Active Cooling Fan, 8,550mAh Battery: See Price
  6. OnePlus Ace 6 Ultra's Key Specifications Surface via Geekbench Listing
  7. Jailer 2 OTT Release Date Reportedly Revealed Online: When and Where to Watch it Online?
  8. Oppo Find X9s Pro Launched With 200-Megapixel Cameras: See Price, Features
  9. Samsung Galaxy S27 Ultra Might Arrive With This Battery Upgrade
  10. Oppo Pad 5 Pro With 13,380mAh Battery Debuts Alongside Pad Mini: See Prices
  1. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
  2. OCBC Partners Lion Global Investors and DigiFT to Launch Tokenised Gold Fund With GOLDX Token
  3. Oppo Pad 5 Pro Launched With 13,380mAh Battery, Snapdragon 8 Elite Gen 5 SoC Alongside Oppo Pad Mini: Price, Features
  4. Redmi K90 Max Launched With Dimensity 9500 SoC, 8,550mAh Battery and Active Cooling Fan: Price, Specifications
  5. Oppo Find X9 Ultra Launched With Snapdragon 8 Elite Gen 5 SoC, 200-Megapixel Periscope Camera: Price, Specifications
  6. Oppo Find X9s Pro Launched With 200-Megapixel Cameras, 7,025mAh Battery: Price, Specifications
  7. OnePlus Ace 6 Ultra Geekbench Listing Reveals MediaTek Dimensity 9500 Chip, 16GB RAM
  8. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
  9. Deezer Claims 75,000 AI-Generated Songs Are Being Uploaded to the Platform Daily
  10. Heartbeat Season 2 OTT Release Date: Know When and Where to Stream This Medical Drama Online
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.