Voting as a trap: vulnerability in Counter Strike 2 reveals players personal data

Brother

Professional
Messages
2,565
Reputation
3
Reaction score
362
Points
83
The community recommends that you refrain from playing the game until the issues are resolved.

Popular shooter Counter-Strike 2 was under threat due to the discovered vulnerability that allows attackers to gain access to personal data of players.

This is done in a very clever and unobvious way. At the first stage, the attacker changes his nickname in the Steam profile to HTML code containing a link to the image in any format. Then the hacker initiates a vote in the game, for example, for a "kick" of one of the players. When the voting window appears on the screen of other players, malicious code sewn into the image by the link is executed and steals the data of gamers connected to the game.

In the video below, the attacker got the IP addresses of all the players in the session. However, there is a risk that other sensitive data may be collected through the detected vulnerability.


The Counter-Strike 2 community recommends that you refrain from playing the game until the vulnerability is fixed.
 
Top