A critical Metal Gear Online vulnerability could have allowed attackers to compromise players’ computers through a malicious online lobby. The issue affected Metal Gear Online 3, the multiplayer mode included with Metal Gear Solid V.
Tracked as CVE-2026-19874, the flaw received a critical severity score of 9.1 out of 10. Konami has fixed the problem in version 1.1.2.9.
Malicious lobbies could trigger remote code execution
The vulnerability involved data sent through Steam game lobbies. Metal Gear Online 3 did not properly verify one of the fields received from a lobby host.
As a result, an attacker could create a malicious lobby and potentially execute code on the computer of any player who joined it. Victims did not need to click a link, download a file or take further action after entering the match.
CERT/CC warned that the flaw could allow one attacker to compromise several players during a single game.
Host transfer increased the risk
Attackers did not necessarily need to create a new lobby from scratch. In Metal Gear Online 3, host privileges move to another participant if the current host leaves.
Therefore, an attacker could join an active match, obtain host control and then send malicious lobby data to everyone still connected.
This made the Metal Gear Online vulnerability especially dangerous for players in public multiplayer matches.
Overflow bug corrupted sensitive memory
The issue centred on the kick_num field, which records the number of players removed from a lobby. The game also processes Steam IDs linked to those removed players.
However, the game failed to confirm that the supplied number stayed within safe limits. A malicious host could provide more data than the allocated memory buffer could hold.
The excess data could then overwrite nearby memory regions, including internal Steamworks structures used to process lobby updates and messages. That could let an attacker redirect the game’s execution flow.
Successful exploitation could result in arbitrary code running inside the affected game process.
Konami blocks outdated versions from online play
Konami addressed the flaw with executable version 1.1.2.9. The update also changed server and lobby versions, preventing older game clients from accessing online services.
Konami had not published detailed patch notes or a separate security advisory at the time of disclosure. Players should update Metal Gear Online 3 before joining online matches.


0 responses to “Metal Gear Online Vulnerability Lets Hackers Hijack Player PCs”