How One Twitch Chat Message Became Code Execution on a Streamer’s PC
Summary
The article details a chain where a Twitch chat message, processed by an OBS Browser Source, leads to remote code execution on a streamer’s PC. It explains how an unsanitized chat overlay combined with an unsandboxed Chromium in OBS, and a known V8 vulnerability (CVE-2024-7971), enabled viewer-controlled HTML/JavaScript to escape into native code. The piece also describes OBS’s mitigations, including upgrading the embedded browser and re-enabling the sandbox, and offers practical guidance for securing streaming setups.