Source: Ars Technica
A USB-connected peripheral can execute arbitrary code on a PC by exploiting how operating systems handle device firmware updates, bypassing user interaction entirely. This matters because it exposes a gap in OS security: vendors have hardened network and software attack surfaces while treating connected hardware as inherently trusted, leaving any peripheral a potential backdoor if its firmware is compromised or intercepted in transit.