Security researcher chains Twitch overlay flaw to remote code execution in OBS
A researcher demonstrated that an unsanitized Twitch chat overlay running as an OBS Browser Source could let a viewer inject JavaScript into OBS's embedded Chromium browser. Because that Chromium build shipped in OBS 32.2.2 ran without its sandbox and included a V8 engine still vulnerable to the already-exploited CVE-2024-7971, the researcher was able to turn a single chat message into full code execution on the streamer's machine, using default OBS settings.
GoKawiil's interpretation of the reporting above, not reported fact.
The finding suggests that widely used, community-built streaming add-ons can introduce serious risk even when the core software (OBS) itself isn't directly at fault, since third-party overlays often handle untrusted viewer input with little scrutiny. It also highlights how delays in shipping patched Chromium/V8 versions inside embedded browsers can leave known, actively exploited bugs open in unrelated applications long after fixes exist elsewhere.
- A chat overlay that rendered viewer messages as raw HTML created a classic XSS vulnerability feeding into OBS.
- OBS 32.2.2 ran its embedded Chromium without sandboxing and with a V8 version still vulnerable to CVE-2024-7971.
- The combination allowed a single Twitch chat message to achieve remote code execution on a streamer's PC using default settings.
Source: blog.scrt.ch, 2026-09-26
Published there as: “How one Twitch chat message became code execution on a streamer’s PC”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.