proomt

Search

Search posts, papers, and topics

All posts

Hacker News front pageDylan Iffrig-Bourfa6 min readadvanced

How one Twitch chat message became code execution on a streamer’s PC

Summary

A vulnerable Twitch chat overlay, combined with an unsandboxed Chromium renderer in OBS and a known V8 exploit (CVE-2024-7971), allowed a viewer to achieve remote code execution on a streamer's PC. This chain turned a single malicious chat message into full control of the host machine.

  • Many OBS Browser Sources, like chat overlays, render untrusted web content, making XSS a critical vulnerability.
  • OBS's embedded Chromium (CEF) instance was configured without its security sandbox, removing a key isolation layer.
  • The Chromium version in OBS was significantly outdated, containing a V8 type confusion vulnerability (CVE-2024-7971) actively exploited in the wild.
  • The combination of XSS, unsandboxed Chromium, and a known V8 exploit enabled remote code execution from a chat message.

This post matters to streamers, overlay developers, and security engineers as it details a critical RCE vulnerability chain in a widely used streaming application, highlighting the dangers of outdated embedded browsers and disabled sandboxes.

8/10

Related reading

  1. Out-of-Order HTML Streaming Moves from JS Frameworks into the Browser

    The WICG declarative partial updates proposal adds `<template for>` and processing‑instruction markers to enable out‑of‑order HTML streaming directly in the browser. Chrome 150 ships the markup support; streaming DOM APIs (e.g., `streamHTMLUnsafe`) and `Response.textStream()` let servers push fragments that replace placeholders without blocking the rest of the page. Security is enforced by limiti…

    InfoQinfoq.com2 min
  2. ChatGPT now knows what you do on other websites via ad collector

    OpenAI’s ChatGPT sets a cross‑site cookie (__obi) that advertisers’ ad‑pixel scripts automatically send back to OpenAI, linking browsing activity on third‑party sites to a user’s ChatGPT account. The author reverse‑engineered the token exchange, captured traffic from hundreds of pixels, and quantified the data collected (emails, phone numbers, locations, page paths). The mechanism works for logge…

    Hacker News front pagebuchodi.com5 minHN758393lobste.rs59
  3. From alert to resolution: Manage incidents with Bits Chat in Slack

    Datadog’s Bits Chat adds a natural‑language interface to Slack, letting responders start investigations, get root‑cause analysis, generate code fixes, and close incidents without leaving the channel. The post walks through a sample e‑commerce outage to show the end‑to‑end workflow.

    Datadogdatadoghq.com4 min
  4. Tapjacking Protection: Rejecting Android Touches Behind an Overlay

    Codename One adds tapjacking protection to its Android runtime. It detects fully or partially obscured MotionEvents, offers four policies (OFF, REPORT, BLOCK, STRICT), can block the entire gesture, and on Android 12+ can request the system hide overlay windows. The API is exposed via `DeviceIntegrity.setTapjackingProtection` and a listener for state changes. iOS has no overlay threat, so the feat…

    CodeName Onecodenameone.com3 min