A vulnerability in MECCHA CHAMELEON let a malicious Steam Workshop custom-map lobby host execute attacker-controlled code on a joining player's Windows system. The game's Blueprint logic exposed an Unreal Engine recording-output function that attackers could use to write arbitrary files through controlled paths; a null-character path-handling discrepancy bypassed Unreal's automatic .wav filename suffix.
Researchers demonstrated a two-click attack chain by embedding an HTML Application payload in uncompressed PCM WAV data, writing it to the Windows Startup folder, and relying on mshta.exe to run the payload after the victim restarted the system. Version 4.0.0 remediated the issue by preventing StopRecordingOutput from creating files; researchers reported finding no Workshop maps exploiting this specific flaw.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
MECCHA CHAMELEON version 4.0.0 was released on 20 August 2026 with a patch for the vulnerability. Following the change, StopRecordingOutput no longer creates files, including legitimate recording-output files.
The developer replied to the researchers on 17 August 2026 and said the reported issue would be fixed.
Between 11 and 17 August 2026, researchers attempted to report a custom-map vulnerability through Twitter, Discord, Steam Support, and the developer email address. The flaw allowed a malicious lobby host's Workshop map to use Blueprint-accessible recording output to write an attacker-controlled payload into a joining player's Windows Startup folder, leading to code execution after restart.
Researchers reviewed Steam Workshop maps and found no maps exploiting this specific vulnerability.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.