Valve just patched a major Steam exploit you didn't know about

It’s been a bad day on Steam, as a nasty exploit has been lurking on the site – not for the first time – ready to trap the unwary and compromise their accounts. But the good news is that Valve has literally just patched the flaw with a swift response.

To be specific, this was an XSS exploit (cross-site scripting) which, as Eurogamer spotted, was initially highlighted by a moderator on Steam's official Reddit around eight hours ago.

The vulnerability let malicious parties inject their own code in order to compromise an account – potentially allowing the attacker to perform actions on said account that don’t need the password reconfirming, or they could attempt to redirect the owner to a phishing site to grab their login details.

Profile pitfall

According to the mod in question, this was triggered just by viewing a dodgy profile page, or your own activity feed, but both these areas have now been patched up and fixed.

However, if you’ve been clicking around Steam profiles earlier today, or the activity feed, that could obviously be a worry. There’s no sure way to tell if you have been affected at this point, unfortunately, save for – obviously enough – odd things happening to your Steam account. Fingers crossed that isn’t the case.

As mentioned, this isn’t the first time we’ve witnessed an exploit hitting the Steam site, or indeed serious privacy woes like the time just over a year ago when people’s account details (including credit card data) became visible to some other users (rather than their own information).

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Gaming
inZOI.
inZOI early access is the most disappointed I’ve been with a game in years
A screenshot from The First Berserker: Khazan
I got absolutely destroyed by The First Berserker: Khazan’s bosses for hours on end and loved every second of it
A screenshot from Indiana Jones and the Great Circle showing Indiana Jones
Indiana Jones and the Great Circle finally gets PS5 release date and I can't wait to don the fedora and crack the whip
A Minecraft sheep.
Minecraft developer rejects generative AI, 'it's important that it makes us feel happy to create as humans'
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Tuesday, March 25 (game #653)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Latest in News
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening