Sleeping Bouncer Bug Raises Security Concerns for Top PC Hardware Brands

Riot Games has disclosed a critical security flaw impacting several major motherboard manufacturers, potentially allowing malicious code injection during system boot.

The vulnerability, known internally as the “Sleeping Bouncer” bug, affects firmware implementations of a key hardware security feature that prevents unauthorized Direct Memory Access (DMA).

The Issue: Faulty IOMMU Initialization

According to the Riot Vanguard team, the flaw lies in how some modern motherboards initialize the Input-Output Memory Management Unit (IOMMU).

This system component acts as a “bouncer” for a computer’s RAM, regulating which devices can access memory.

When functioning correctly, IOMMU blocks unauthorized hardware attacks, especially from DMA-based cheats and exploits that inject code into memory before the operating system loads.

However, Riot’s engineers found that certain firmware implementations falsely reported that “Pre-Boot DMA Protection” was active, even though the IOMMU had not been initialized adequately during early boot.

This left a brief but critical window in which rogue devices or hardware cheats could inject malicious code before anti-cheat tools like Vanguard or even Windows security layers became active.

The issue affects multiple manufacturers, including ASUS, Gigabyte, MSI, and ASRock. These vendors have since issued BIOS and firmware patches to fix the flawed IOMMU initialization.

The associated vulnerabilities have been tracked under identifiers such as CVE-2025-11901 (ASUS), CVE-2025-14302 (Gigabyte), CVE-2025-14303 (MSI), and CVE-2025-14304 (ASRock). Additional technical details are available in the CERT case VU#382314.

Vanguard’s Response and User Impact

Riot Games’ anti-cheat system, Vanguard, will soon begin enforcing stricter checks on affected systems.

If Vanguard detects that a player’s system lacks proper firmware protections or exhibits anomalies consistent with vulnerable configurations, it will apply a temporary VAN: Restriction notice.

This prevents access to Valorant until the system’s security settings are corrected or the firmware is updated.

Riot clarified that receiving such a restriction does not imply cheating; it indicates a system configuration that compromises Vanguard’s integrity guarantees.

Players can restore access by enabling Secure Boot and IOMMU, or by updating firmware per the manufacturer’s official advisories.

This discovery marks one of the first real-world examples of game security research influencing firmware-level fixes across the PC hardware industry.

Riot’s findings prompted industry-wide updates that strengthen pre-boot memory protection and reinforce fair play enforcement systems.

While low-level firmware patches may not sound as exciting as mass ban waves, Riot says the fix closes off an “entire class” of previously undetectable threats, making it significantly harder for DMA-based cheats to operate.

By cooperating with major OEMs, Riot has effectively raised the industry’s baseline security and set a new standard in trusted gaming environments.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Priya
Priya
Priya is a Security Reporter who tracks malware campaigns, exploit kits, and ransomware operations. Her reporting highlights technical indicators and attack patterns that matter to defenders

Trending News

Related Stories