They're hacking USBs now
Vulnerabilities in the FAT FS file system library used in embedded devices like the Flipper Zero can be exploited via corrupted USB/SD cards to crash devices or enable jailbreaks.
These flaws allow physical access attacks on critical infrastructure and consumer devices that rarely receive security updates, creating persistent risks.
Section summaries
The video opens with the host introducing low-level USB/SD card exploits using the Flipper Zero as an example. It explains that vulnerabilities in the FAT FS file system library—used in millions of embedded devices—allow attackers to crash or jailbreak devices by inserting corrupted storage media. The segment emphasizes the simplicity of the attack (mirroring classic 'drop a USB' tactics) and introduces RunZero's discovery of these flaws, including buffer overflows in functions like get volume label parsing.
- FAT FS library vulnerabilities enable physical access attacks on embedded devices
- Exploitation requires only inserting a corrupted USB/SD card
- RunZero identified multiple critical flaws in the library
Sets the foundation for understanding the exploit mechanism and its implications
The video transitions to a sponsorship segment for Flare, a threat intelligence platform that monitors dark web sources for compromised credentials. The host demonstrates how Flare integrates with systems like Entra ID to alert users when their credentials appear in threat feeds, reducing breach response time from hours to minutes. The segment ends with a call to action to try Flare's free offer before it expires.
- Flare provides real-time dark web credential monitoring
- Integration with Entra ID and other systems streamlines threat detection
- Free trial offer expires in 3 days
Commercial content unrelated to the technical vulnerability explanation
The host revisits the FAT FS vulnerability, focusing on the buffer overflow in the get volume label function. A code walkthrough shows how the library copies data into a fixed-size buffer without length checks, enabling attackers to overwrite memory and crash devices. The segment explains that the Flipper Zero uses this vulnerable library and demonstrates how inserting a corrupted SD card triggers a bus fault, returning control to address 0x41414141 (a common exploit marker).
- Buffer overflow in get volume label function lacks bounds checking
- Flipper Zero crashes when exposed to corrupted SD card data
- Exploit overwrites program counter with 0x41414141
Critical for understanding the technical exploit mechanism
The video concludes with a live demonstration of the exploit on the Flipper Zero, showing a bus fault caused by the buffer overflow. The host references HD Moore's proof-of-concept tools (Vol's 2026 FAT FS Chance) and speculates that AI may have contributed to discovering these vulnerabilities. The segment ends with a promotion for the host's AI-focused vulnerability video and a sign-off.
- Exploit successfully crashes Flipper Zero via corrupted SD card
- Proof-of-concept tools available for testing vulnerabilities
- AI's potential role in identifying legacy code flaws
Demonstrates exploit success and ties technical content to broader AI trends
Key points
- FAT FS Vulnerabilities in Embedded Systems — The FAT FS library (vulnerable versions used in STM32 microcontrollers) contains buffer overflows and integer errors in functions like get volume label parsing, exploitable via corrupted storage media.
- Physical Access Exploits — Attackers need only insert a maliciously crafted USB/SD card into a vulnerable device to trigger the exploit, mimicking classic 'drop a USB' social engineering tactics.
- RunZero's Discovery and Disclosure — HD Moore's company RunZero identified multiple vulnerabilities (integer overflows, stack overflows) in FAT FS implementations across embedded systems.
- Lack of Mitigations in Embedded Devices — Many embedded systems lack modern protections like ASLR and NX, making exploitation trivial once vulnerabilities are triggered.
- Flipper Zero as Case Study — The Flipper Zero's STM32W chip uses the vulnerable FAT FS library, and inserting a corrupted SD card can crash or jailbreak the device.
“All you have to do is take a fat file system that is corrupted in a way that exploits the vulnerability and... plugging in the disk and having the OS or the system scan the FA file system is what exploits the bug.” — Video Host
“There is no length check... this effectively is a strcpy that lands in label.” — Video Host
AI-generated from the transcript. May contain errors.
Continue with YouTLDR
Analyze another video with Pro
Process a new video, search every timestamp, compare sources, and keep the result in your library.
More transcripts
Explore other videos transcribed with YouTLDR.

Opus 5 released! Is it better than Fable?
Mastra · English

Leilão de Embriões Nelore PO DNA Genética Aditiva
LANCE RURAL OFICIAL · Portuguese (Portugal, Brazil)

Leilão Peso Pesado Rima Agropecuária
LANCE RURAL OFICIAL · Portuguese (Portugal, Brazil)

النبي .. جبران خليل جبران .. إقرا بودانك
اقرا بودانك · Arabic

Leilão Internacional CIA
LANCE RURAL OFICIAL · Portuguese (Portugal, Brazil)

23° Mega Leilão Genética Aditiva - 1ª Etapa Fêmeas Nelore PO
LANCE RURAL OFICIAL · Portuguese (Portugal, Brazil)

كتاب رسالة الغفران
كتابي المنقذ · Arabic

Erkenntnistheorie 7 Immanuel Kant II
Dominik Finkelde - Hochschule f. Philosophie · English

Schwarze Löcher Erklärt - Von der Geburt bis zum Tod
Dinge Erklärt – Kurzgesagt · German

Como construir uma esfera de Dyson – A Megaestrutura Suprema
Em Poucas Palavras – Kurzgesagt · Portuguese (Portugal, Brazil)

[Histoire des sciences] L’histoire de l’intelligence artificielle (IA)
CEA · French

ميكانيكا الكم│1│الواقع الوهمى - كيف بدأ الكم ؟!
Sharafestien - شرفشتــاين (Sharafestien) · Arabic