Hacker News front pageDylan Iffrig-Bourfa6 min readadvanced
How one Twitch chat message became code execution on a streamer’s PC
Summary
A vulnerable Twitch chat overlay, combined with an unsandboxed Chromium renderer in OBS and a known V8 exploit (CVE-2024-7971), allowed a viewer to achieve remote code execution on a streamer's PC. This chain turned a single malicious chat message into full control of the host machine.
- Many OBS Browser Sources, like chat overlays, render untrusted web content, making XSS a critical vulnerability.
- OBS's embedded Chromium (CEF) instance was configured without its security sandbox, removing a key isolation layer.
- The Chromium version in OBS was significantly outdated, containing a V8 type confusion vulnerability (CVE-2024-7971) actively exploited in the wild.
- The combination of XSS, unsandboxed Chromium, and a known V8 exploit enabled remote code execution from a chat message.
This post matters to streamers, overlay developers, and security engineers as it details a critical RCE vulnerability chain in a widely used streaming application, highlighting the dangers of outdated embedded browsers and disabled sandboxes.
8/10



