A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory access that may potentially lead to an attacker leaking sensitive information or achieving code execution.
https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4001