Analysis shows Lenovo, Acer, HP, Dell, and Asus are shipping laptops with bloatware that's known to be insecure
The Duo Security Bulletin :
Context & Ripple Effects
This report lands on familiar territory for Lenovo, whose 2015 Superfish episode saw SSL-busting code spread to a dozen more apps and an anti-theft component that reinstalled unwanted software as a rootkit — followed by a widely mocked public response at the time. What the Duo Labs analysis adds is scope: insecure preinstalled software is not a Lenovo pathology but a practice spanning all five top PC vendors.
The finding also reframes where laptop risk lives. Later coverage shows the attack surface migrating deeper than user-space apps, from Cisco Talos' flaw in Dell's ControlVault security firmware to Binarly's finding that UEFI Secure Boot was compromised across 200+ device models via a leaked cryptographic key.
First-order effects
- Lenovo moves first within days, telling users to uninstall its Accelerator app after confirming it is vulnerable to man-in-the-middle attacks — a direct admission tied to the Duo Labs findings.
- Buyers of new laptops from any of the five named vendors inherit attack surface they did not choose: preinstalled software with known insecurities ships enabled by default.
Second-order effects
- Every major OEM is now exposed to the same researcher playbook, forcing vendor-by-vendor audits of bundled utilities rather than one-off patches — the Accelerator advisory sets the template for reactive uninstalls.
- Security teams and enterprise buyers gain a new procurement criterion, weighing what ships preinstalled alongside price and specs when selecting laptop fleets.
Third-order effects
- If the pattern holds, preinstalled OEM software — apps, firmware, and provisioning keys alike — becomes a standing, systemic attack surface for the PC industry, with responsibility split awkwardly between chipmakers, OEMs, and software vendors.
- The trajectory from bloatware apps toward ControlVault-class firmware and Secure Boot failures points toward regulators and enterprises treating the laptop supply chain itself, not just end-user software, as the security perimeter.
The trend: PC security scrutiny is moving up the stack from bundled adware to firmware and provisioning keys, turning the OEM supply chain into the industry's defining attack surface.