Skip to content
Twitch Chat Messages Exploit OBS Studio via Chromium Vulnerability

Twitch Chat Messages Exploit OBS Studio via Chromium Vulnerability

First seen 25 Sep 2026, 23:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 26, 2026 at 00:29 UTC
  • •Malicious Twitch messages can exploit OBS Studio versions 32.2.2 and older.
  • •The attack leverages CVE-2024-7971, a known type-confusion vulnerability.
  • •OBS is upgrading its security features to address this critical flaw.

A vulnerability in OBS Studio allows malicious Twitch chat messages to execute native code on streamers' Windows PCs. This exploit targets users running OBS Studio version 32.2.2 or older, leveraging a cross-site scripting (XSS) flaw in custom overlays that render viewer messages as unsanitized HTML. The attack exploits CVE-2024-7971, a type-confusion vulnerability in the V8 JavaScript engine, which has been linked to real-world attacks by North Korean threat actors. The attack chain involves executing JavaScript within the OBS overlay, which can then exploit the outdated Chromium engine due to the disabled sandbox. While default installations of OBS are not vulnerable, using untrusted Browser Source content creates a significant risk. The OBS team is currently working on security enhancements to mitigate this vulnerability. The issue was reported on August 19, 2026, and publicly disclosed on September 22, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-08-21
CVE-2024-7971 published
Google disclosed a type-confusion vulnerability in the V8 JavaScript engine, affecting Chromium.
Cyberinsider
2024-08-26
CVE-2024-7971 added to CISA KEV
CISA included CVE-2024-7971 in its Known Exploited Vulnerabilities catalog due to active exploitation.
Cyberinsider
2026-02-01
Research on vulnerability begins
Orange researchers started investigating after observing a custom Twitch overlay screenshot showing code execution.
Cyberinsider
2026-07-01
Complete attack chain reproduced
Orange successfully demonstrated the full exploit chain on an updated Windows 11 system.
Cyberinsider
2026-08-19
Vulnerability reported to OBS team
Orange disclosed the vulnerability to the OBS team, prompting security discussions.
Cyberinsider
2026-09-22
Public disclosure of vulnerability
The vulnerability was publicly disclosed, raising awareness among streamers and developers.
Cyberinsider

More articles in this cluster (2)

Following this threat?

Track Citrine Sleet and CVE-2024-7971 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed