Hacker News·7 min read

How one Twitch chat message became code execution on a streamer’s PC

T
tau255
How one Twitch chat message became code execution on a streamer’s PC
✦Dive DeeperCreate a free account to unlock

A vulnerable chat overlay, an unsandboxed Chromium renderer, and a V8 bug already exploited in the wild were enough to turn viewer-controlled text into native code execution, with OBS itself left at its default settings.

I found a Twitch chat overlay that rendered viewer messages as raw HTML inside an OBS Browser Source. That gives a viewer JavaScript execution inside OBS’s embedded Chromium browser. The latest release of OBS at the time shipped a Chromium build that ran without its normal sandbox, and its V8 version was still vulnerable to CVE-2024-7971 , a bug already exploited in the wild.

Put together, the message started in Twitch chat and ended in full control of the streamer’s machine.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in