Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution.
XSOverlay exposes a local WebSocket API for communication with the application. The flaw lies in the lack of proper source verification for incoming connections (CWE-1385 — Missing Origin Validation in WebSockets), allowing external, non-local websites to connect to this API. An attacker can thus send malicious commands directly to the application running on the user's computer, leading to arbitrary code execution.
An attacker gains the ability to execute arbitrary code on the victim's device, which may result in complete system compromise, data theft, or installation of malicious software.
XSOverlay should be updated to build 647 or newer. Details are available in the vendor's official references and in the announcement on the Steam platform.
XSOverlay by Xiexe in all versions before build 647
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H