Scworld Twitch Chat Messages Exploit OBS Studio via Chromium Vulnerability
Article Content
- •Malicious Twitch messages can exploit OBS Studio versions 32.2.2 and older.
- •The attack leverages CVE-2024-7971, a known type-confusion vulnerability.
- •OBS is upgrading its security features to address this critical flaw.
A vulnerability in OBS Studio allows malicious Twitch chat messages to execute native code on streamers' Windows PCs. This exploit targets users running OBS Studio version 32.2.2 or older, leveraging a cross-site scripting (XSS) flaw in custom overlays that render viewer messages as unsanitized HTML. The attack exploits CVE-2024-7971, a type-confusion vulnerability in the V8 JavaScript engine, which has been linked to real-world attacks by North Korean threat actors. The attack chain involves executing JavaScript within the OBS overlay, which can then exploit the outdated Chromium engine due to the disabled sandbox. While default installations of OBS are not vulnerable, using untrusted Browser Source content creates a significant risk. The OBS team is currently working on security enhancements to mitigate this vulnerability. The issue was reported on August 19, 2026, and publicly disclosed on September 22, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Citrine Sleet and CVE-2024-7971 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These vulnerabilities allow local attackers to escalate privileges to SYSTEM level, posing significant risks to…