A malicious Twitch chat message could be turned into native code execution on a streamer’s Windows PC by chaining a vulnerable OBS overlay with an outdated Chromium vulnerability. The attack requires the streamer to be using OBS Studio 32.2.2 or older without changing its default security settings. The research began after Orange researchers noticed a screenshot posted by a friend showing code from a custom Twitch chat overlay. The overlay inserted viewer messages directly into the page as HTML without sanitization, creating a cross-site scripting (XSS) flaw that allowed a Twitch viewer to execute JavaScript inside the overlay. Orange began coordinating with the overlay developer in February 2026 and later reproduced the complete attack chain on an updated Windows 11 system in July. The issue was reported to the OBS team on August 19, ahead of public disclosure on September 22. OBS Studio is a widely used open-source application for livestreaming and video recording. Its Browser Source feature allows streamers to display web-based content such as chat boxes, donation alerts, follower notifications, animations, and other interactive widgets directly inside a scene. These Browser Sources are rendered using Chromium through the Chromium Embedded Framework (CEF). That meant the vulnerable overlay was
Read More











