Moneycontrol PRO
Black Friday Sale
Black Friday Sale
HomeNewsTrendsA security flaw discovered in EA's Origin app leaves millions of Windows users exposed to hackers

A security flaw discovered in EA's Origin app leaves millions of Windows users exposed to hackers

The flaw in the Origin app allows hackers to trick users into opening and running malicious software on their systems.

April 18, 2019 / 16:48 IST

Electronic Arts recently fixed a bug in their online gaming platform, Origin. The Origin app is EA’s answer to game services like Steam and Epic storefronts. Origin boasts a massive archive of games including some major titles like Apex Legends, Anthem, Battlefield V, Assassin’s Creed Odyssey and many more.

A recently discovered security vulnerability in EA’s popular gaming app has exposed tens of millions of Windows users to cyber-attacks. The flaw in the Origin app allows hackers to trick users into opening and running malicious software on their systems.

The Origin desktop client’s URL scheme allows users to open the app and load a game from a web page by clicking a link with “origin://” in the address. However, two security researchers discovered that the app could be duped into running any app on an unsuspecting victim’s PC.

According to the security researchers, the bug occurred when players used EA Origin client but requested to edit their account on EA.com. A statement Beard made to Zdnet read, “The EA Origin client will spit out an auto-login URL, in which the token is basically the equivalent of your active username and password."

Now, while such auto-login URLs are commonplace in many web-based and desktop apps, the URLs can only be accessed by the user. However, this wasn’t the case, according to Beard, anyone could easily access these token auto-login URLs if the account were being used on an unsecured network or WiFi hotspot.

Additionally, IoT malware/botnets that have infected home routers will allow criminals to automate the mass collection of EA account data by using these auto-login URLs. Hackers can also use these URLs to collect information such as last digits of a user’s phone number, order history, last four digits of a saved credit card, a user’s real name and more.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Carlsen Martin
first published: Apr 18, 2019 04:48 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347