logo

MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution

ID: a003e868-cae0-56be-b5bc-98932010077d

STIX ID: report--a003e868-cae0-56be-b5bc-98932010077d

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-09-04

Date Updated: 2026-09-11

Author: Divya

...
...

Aikido Security disclosed a vulnerability in MECCHA CHAMELEON's use of Unreal Engine that allowed malicious Steam Workshop maps to use the FinishRecordingOutput Blueprint node to write arbitrary files (including HTA payloads embedded in PCM WAV data) to user-writable locations such as the Windows Startup folder, producing delayed remote code execution after reboot; the issue was patched in MECCHA CHAMELEON v4.0.0 and researchers found no evidence of active exploitation in existing Workshop maps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.