A malicious Twitch chat message could trigger native code execution on a streamer's Windows PC running OBS Studio 32.2.2 or older by exploiting an unsanitized XSS vulnerability in a custom chat overlay combined with CVE-2024-7971, a V8 vulnerability in the bundled Chromium engine. The attack chain was discovered by Orange researchers and disclosed after coordination with the OBS team. OBS is addressing the issue by upgrading to Chromium 128 and testing sandbox re-enablement.