Security researchers disclosed multiple code-execution risks affecting Facebook-related software. Facebook Gameroom accepted insufficiently validated game identifiers in a custom URI scheme, allowing attackers to redirect its embedded browser to attacker-controlled Facebook Page content. The client used an obsolete CefSharp/Chromium build—Chromium 63.0.3239.132 while Chromium 86 was current—potentially exposing users to browser vulnerabilities; researchers demonstrated a crash using CVE-2018-6056. Facebook rated the URI-scheme issue High and patched it. A separate Facebook-related report described remote code execution involving MobileIron MDM.
Gameroom also deserialized the user-writable fbgames.settings file with .NET BinaryFormatter, enabling local code execution, although Facebook determined it lacked a practical remote path or privilege-escalation impact. The findings align with broader research showing that unsafe deserialization is not limited to Java binary streams: JSON, XML, and .NET serializers can permit remote code execution when untrusted input controls object types or reaches dangerous constructors, setters, converters, or gadget chains. Organizations should prevent untrusted data from reaching deserializers, remove or tightly constrain polymorphic type handling, and enforce strict type allowlists.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Alvaro Muñoz and Oleksandr Mirosh published research for Black Hat 2017 showing that unsafe JSON, XML, binary, and custom-format deserialization can enable remote code execution. The paper documented insecure configurations and vulnerabilities including Breeze CVE-2017-9424, NancyFX CVE-2017-9785, and DotNetNuke CVE-2017-9822.
Facebook released Gameroom, a Windows-native gaming client that used an embedded Chromium-based browser through CefSharp.
Java deserialization vulnerabilities gained major attention in 2016, according to the research paper.
Frohoff and Lawrence published an Apache Commons-Collections remote-code-execution gadget, accelerating research into Java deserialization attacks.
The research states that Java deserialization vulnerabilities had been known since at least 2011.
Facebook rated as High and patched a Gameroom custom URI-scheme vulnerability that could redirect the embedded browser to attacker-controlled Facebook Page custom-tab content. The issue could expose users to vulnerabilities in Gameroom's outdated Chromium 63 browser engine and enable phishing-style dialogs.
Breeze released version 1.6.5 to fix its unsafe Json.Net deserialization vulnerability.
Researchers reported that Breeze used Json.Net with TypeNameHandling.All and an Object Tag property in SaveOptions, enabling arbitrary code execution tracked as CVE-2017-9424.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.