Seven flaws in a tiny bit of code could shake millions of gadgets
runZero found bugs in FatFs, the filesystem library hiding inside cameras, drones and hardware crypto wallets. Patches are already trickling out, but the fix will take years.

Key points
- Security firm runZero disclosed seven vulnerabilities in FatFs, a tiny piece of software used to read USB drives and SD cards inside millions of embedded devices.
- FatFs ships inside security cameras, drones, industrial controllers and hardware crypto wallets built on popular chip platforms.
- The flaws can be triggered by plugging in a booby-trapped USB stick or memory card, giving an attacker a foothold on the device.
- Because FatFs is copied into each vendor's firmware, there's no central update, every device maker has to ship its own patch.
Here is a problem that'll age badly.
Security firm runZero has disclosed seven bugs in something called FatFs. Most people have never heard of it. Almost everyone owns a device that runs it. RunZero, worth noting, is the firm Accenture moved to acquire in June as part of a $4.1 billion OT security consolidation.
FatFs is a small library that lets a gadget read and write files on a USB stick or SD card in the same format Windows uses. It's free, it's compact, and for two decades chip makers and device engineers have quietly dropped it into their products because it just works.
That's the problem. It's everywhere, and nobody keeps a central list of where.
Which devices are affected?
Any device that reads a USB drive or memory card and was built on top of FatFs. That includes security cameras, consumer drones, industrial controllers and hardware crypto wallets, the little USB gadgets people use to store Bitcoin offline. Medical, automotive and smart-home firmware also show up in the exposure surface.
RunZero's writeup, first reported by The Hacker News, describes seven separate flaws in how FatFs handles the layout of a FAT or exFAT disk. In plain English: craft a malicious USB stick or SD card, get it plugged into a vulnerable device, and the code that reads the card can be tricked into corrupting the device's own memory.
From there, a skilled attacker can potentially run their own code on the device. That's the worst-case outcome for a hardware wallet holding someone's savings, or a camera watching a hospital corridor.
How does an attack actually happen?
Someone has to get the poisoned storage into the device. That sounds like a big ask. In practice it isn't.
A dropped USB stick in a car park is a classic trick. A shared SD card between drone hobbyists. A repair technician swapping a memory module. An attacker with five minutes of physical access to a kiosk or an industrial panel. These devices were never designed to distrust the storage plugged into them.
Unlike a phone or a laptop, most of them will never phone home for an update.
Why the fix will take years
FatFs is what engineers call a source library. Every vendor takes a copy, bakes it into their firmware and ships it. No auto-update exists, and no single patch covers everyone.
The FatFs maintainer has already published fixes. Now hundreds of device manufacturers have to notice, rebuild their firmware and push it out to customers, assuming they still support the product. Many won't. The postmortem, in a year or two, will confirm that some of these devices were end-of-life before the advisory landed.
Ordinary people can't patch this themselves. But there's a sensible habit worth adopting: don't plug USB sticks or SD cards of unknown origin into anything you care about, especially a hardware wallet or a work device. Treat found storage the way you'd treat a found syringe.
Operational takeaway: if your asset inventory doesn't tell you which of your devices embed FatFs, you don't have an asset inventory.



