| |
A security vulnerability in OBS allowed Twitch chat messages to achieve remote code execution on streamers' computers through a combination of three flaws: an unsanitized chat overlay that rendered viewer messages as HTML, OBS's Chromium browser running without its sandbox, and an unpatched V8 vulnerability already being exploited in the wild. A viewer could send a specially crafted message in Twitch chat that would execute as JavaScript in the overlay, break out of the browser, and gain full control of the streamer's machine with default OBS settings and no streamer interaction required.
Read Full Article →
← More Tech news