Vulnerability Management

Metal Gear Online 3 vulnerability allowed remote code execution

As reported by Cyber Insider, a critical vulnerability in Konami's Metal Gear Online 3 allowed malicious actors to execute arbitrary code on players' computers. The flaw, identified as CVE-2026-19874, was present in the multiplayer lobby system and has since been patched by Konami.

The vulnerability, discovered by researcher Alice Cecchetto and detailed by CERT/CC, stemmed from a heap-based buffer overflow in the game's player-removal mechanism. Malicious lobby hosts could exploit this by sending oversized values for the kick_num field, causing out-of-bounds writes that could corrupt adjacent memory structures. This corruption could redirect program execution, allowing attackers to run their own code, potentially leveraging read-write-execute memory regions protected by Denuvo. Exploitation was automatic upon joining an attacker-controlled lobby, requiring no user interaction.

The issue affected version 1.1.2.8 and was fixed in version 1.1.2.9, released on August 4, 2026. Konami has not issued a specific advisory, but the update prevents older clients from accessing online services. Players are advised to ensure their game is updated to the latest version before engaging in online multiplayer to mitigate the risk.

Source: Cyber Insider

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds