Electronic Arts confirms the existence of a vulnerability in its platform after security researchers found that an unsuspecting gamer could be tricked into remotely executing malicious code on their computer.
The bug affected Windows users who had the Origin app installed. Tens of millions of gamers use the Origin app to purchase, access, and download games. To make it easier to access an individual game's store from the web, the client has its own URL scheme that allows players to open the app and load a game from a web page by clicking a link with origin:// in the address.
Two security researchers from Underdog Security found that the application could be tricked into running any application on the victim's computer.
The researchers shared the proof-of-concept code. The code allowed any application to run at the same privilege level as the logged-in user.

Additionally, a hacker could send malicious PowerShell commands, a built-in application often used by attackers to download additional malicious components and ultimately install ransomware.
A malicious link could be sent as an email or posted on a web page, but it could also be triggered if the malicious code was combined with a cross-site scripting exploit that ran automatically in the browser.
It was also possible to steal a user's account access token using a single line of code, allowing a hacker to gain access to a user's account without needing their password.
EA spokesperson John Reseburg confirmed that they have been working on a fix for the bug since Monday.
