Sponsored By

A now-fixed Origin vulnerability potentially opened the client to hackers

Until just recently, Electronic Arts’ digital game platform Origin had a security vulnerability that could be used run malicious apps on a user’s computer.

Alissa McAloon, Publisher

April 16, 2019

1 Min Read
Game Developer logo in a gray background | Game Developer

Until just recently, Electronic Arts’ digital game platform Origin had a security vulnerability that could be used to run malicious apps on an Origin user's computer.

Researchers speaking to TechCrunch offered a look at the exploit in action, explaining that the flaw itself allowed would-be attackers to use Origin as a channel to trick users into running any app of the attacker’s choosing. 

It was an issue exclusive to the Windows version of the client, and one that the researchers from Underdog Security say took advantage of how Origin uses “origin://“ links to start games by clicking on a link in a webpage. 

Combined with other recourses like PowerShell commands, the exploit could theoretically have been used to download and install malicious programs onto the computers of unsuspecting Origin users that clicked a hijacked link. The bug, which EA confirmed has been fixed as of this Monday, also potentially opened the door for hackers to steal account access tokens using a single line of code.

About the Author

Alissa McAloon

Publisher, GameDeveloper.com

As the Publisher of Game Developer, Alissa McAloon brings a decade of experience in the video game industry and media. When not working in the world of B2B game journalism, Alissa enjoys spending her time in the worlds of immersive sandbox games or dabbling in the occasional TTRPG.

Daily news, dev blogs, and stories from Game Developer straight to your inbox

You May Also Like