MECCHA CHAMELEON Vulnerability Enables Remote Code Execution via Custom Maps

MECCHA CHAMELEON Vulnerability Enables Remote Code Execution via Custom Maps

First seen 4 Sep 2026, 14:46 UTC LinkedinGbhackers 45.0

Article Content

Browse articles
ThreatCluster

A recently patched vulnerability in MECCHA CHAMELEON, a hide-and-seek game, allows attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems. This can lead to remote code execution (RCE) when the victim restarts their device. Security researchers at Aikido Security disclosed this flaw, which affects users who play custom maps. The vulnerability was identified as a delayed RCE issue, and a patch has been released to mitigate the risk. Users are advised to update their game to prevent exploitation. The attack vector relies on the ability of custom maps to abuse certain bugs in the game. The vulnerability impacts Windows systems, but specifics on the number of affected users or systems have not been disclosed.

Key Points: • MECCHA CHAMELEON vulnerability allows RCE via custom Steam Workshop maps. • Attackers can exploit the flaw to write files to arbitrary locations on Windows. • A patch has been released; users should update to mitigate risks.

Ask AI about this cluster

Timeline

2026-09-03
Vulnerability disclosed by Aikido Security
Researchers revealed a flaw in MECCHA CHAMELEON that allows RCE through custom maps.
Linkedin
2026-09-04
Patch released for MECCHA CHAMELEON
A patch was issued to fix the RCE vulnerability, urging users to update their game immediately.
Gbhackers