PSA: Don't install Call of Duty WWII on PC. There's apparently an RCE exploit via game chat people are using to hack each other's PCs.
cyberinsider.com/call-of-duty-…
Call of Duty: WWII Game Pass Launch Stained by Reports of RCE Attacks
Call of Duty: WWII players report being hacked mid-game via an RCE exploit, days after the title was added to Microsoft’s Game Pass lineup.Amar Ćemanović (CyberInsider)
Martin Seeger
in reply to Kevin Beaumont • • •Again? Input validation matters 😏
Reminder: Attacks on Minecraft servers triggered the discovery of log4j.
Kevin Beaumont
in reply to Kevin Beaumont • • •If anybody has any time to burn that Call of Duty thing might be a fun time waste to investigate.
It looks like the same vuln is present in multiple versions of CoD, has never been patched even in supported releases, has no CVE etc. It’s just been ignored while customers get owned.
Andrew Golding
in reply to Kevin Beaumont • • •Demi Marie Obenour
in reply to Kevin Beaumont • • •Nerdy Echidna
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Update
techcrunch.com/2025/07/08/acti…
Activision took down Call of Duty game after PC players hacked, says source | TechCrunch
Lorenzo Franceschi-Bicchierai (TechCrunch)fuzzyfuzzyfungus
in reply to Kevin Beaumont • • •"The game publisher took down only the Microsoft Store and Game Pass version of “Call of Duty: WWII” because they were different versions of the game than listed on Steam, and contained an old flaw that had been patched on other versions of the game"
Did the guy in charge of reminding on-prem Exchange customers that they are unloved children mistake the steam version for a cloud product?
stony kark
in reply to Kevin Beaumont • • •fuzzyfuzzyfungus
in reply to Kevin Beaumont • • •It seems downright criminal to be using RCEs against people in COD: WWII.
Surely COD: Modern Warfare is the correct context?
argv minus one
in reply to Kevin Beaumont • • •I'm surprised this isn't more common. Video game programmers aren't known for their security obsession. There must be tons of vulnerabilities in games.
On macOS this is mitigated by the fact that games don't need very many permissions to run, so the worst any attacker is likely to do to a Mac game is mine crypto until you reboot. But most games run on Windows or Linux, neither of which enforces restrictions like macOS does…
LisPi
in reply to Kevin Beaumont • • •@becomethewaifu How does one even manage to fuckup chat implementation that bad?
This is some /skill/ at failing.