A serious remote code execution vulnerability in the ASUS DriverHub driver management tool made it possible for malicious websites to run commands on computers using the program.
Paul (also known as “MrBruh”), an independent cybersecurity researcher from New Zealand, identified the vulnerability by observing that the software’s validation of orders delivered to the DriverHub background service was inadequate.
By leveraging vulnerabilities identified as CVE-2025-3462 and CVE-2025-3463, the researcher was able to construct an exploit chain that, when combined, accomplishes origin bypass and initiates remote code execution on the target.
When using specific ASUS motherboards, DriverHub, the company’s official driver management application, is installed automatically on the initial system boot read more about ASUS DriverHub flaw let malicious sites run commands with admin rights.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
