67 points•tau255•5 days ago•30 comments•

30 comments

Scryptonite4 days ago
Deja Vu. I had to submit an issue and fix a similar issue years ago -- it was similarly Twitch chat overlay XSS, but for that they (the streamer) at least tried to strip the tags (but it was a poor JS implementation of PHP strip_tags), and the streamer didn't understand the issue until I crafted a image with onload/onerror to freeze/hang the chat overlay.
doodlesdev4 days ago
Fucking absurd. I'll forever hate developers who allow for such _bizarre_ exploit chains to happen. OBS is an OSS project which I believe has received a lot of love throught the years, but having the Chromium sandbox disabled due to authentication with _certain services_ not working with it enabled is asinine. Don't even want to imagine the other problems the project might have waiting to be exploited.

Sure, if the plugin developer sanitized the comments before inserting them, this wouldn't have happened _this way_, but having a browser engine two years outdated (for a reason which IMO is absolutely reasonable compared to other situations before) and having the Chromium sandbox completely disabled with nothing to substitute it is crazy in a software onto which people insert random plugins from the internet to get random functionality.

Hopefully those two changes ship fast to OBS. I may be supporting the project financially in the future if they update their security posture, as I'm generally very fond of OBS.

soulofmischief4 days ago
This would be an interesting writeup if it wasn't so unfocused due to being written or heavily edited by an LLM.
WesSouza4 days ago
“a Twitch chat overlay that rendered viewer messages as raw HTML”

Well damn.

charcircuit4 days ago
https://github.com/obsproject/obs-browser/pull/523

Not even counting the time it took to make this PR, releasing a security update for the browser took 4 months to merge. For reference Brave has a 1 day SLA for releasing the update itself after a security fix gets published.

landr0id4 days ago
It's not just moving a code pointer. They had to migrate CEF runtimes (Alloy to Chrome) which, as I understand from the few minutes of reading I did to understand the complexities outlined in the PR, was necessary because Alloy was removed in M128. So OBS was using the last version of legacy runtime and needed to migrate. I imagine they wanted to do a decent amount of testing to ensure compat.
charcircuit4 days ago
>It's not just moving a code pointer.

That's not the end user's problem. End user's don't want to be told that they got hacked because keeping your product secure was too hard.

Read the full thread on Hacker News →

Related stories