Monday, April 28, 2025
HomeComputer SecurityAccount Take over Vulnerability in EA Origin Game Client Let Hackers Hijack...

Account Take over Vulnerability in EA Origin Game Client Let Hackers Hijack the 300 Million Gamers Account

Published on

SIEM as a Service

Follow Us on Google News

Researcher uncovered a critical chain of vulnerabilities in Popular EA’s Origin gaming client allows attackers to take over the players account and committing the identity theft against 300 Million EA Gamers.

EA (Electronic Arts) is a second largest American based video gaming company who is behind the some of the most famous games including EA Sports titles FIFA, Madden NFL, NHL, NBA Live, and UFC.

The vulnerability resides in the EA origin game client platform can be exploited by abusing the authentication token that used for abandoned subdomains with the OAuth Single Sign-On (SSO) and users login process Trust mechanism.

- Advertisement - Google News

There are several domains including ea.com and origin.com used by EA to provide different services for its gamers that helps users to create a new account and guide to purchase new games in the EA store.

EA Games also configured some of the subdomains under the main domains with DNS address and CNAME records.

During the coordination research conducted by CyberInt and Check Point analyzed one of the EA Games subdomain eaplayinvite.ea.com which is configured with a DNS CNAME and it is pointed to another subdomain ea-invite-reg.azurewebsites.net.

The subdomain used by EA Games hosted in Microsoft Azure (ea-invite-reg.azurewebsites.net) was no longer in use, but the alias record still exists with eaplayinvite.ea.com.

So the researchers opted to register “ea-invite-reg” with Azure that allows them to hijack the subdomain “eaplayinvite.ea.com “ along with the interception of any legitimate EA Games’ user requests.”

According to cyberint, “Having seized control of the eaplayinvite.ea.com subdomain guided research toward the new goal of examining how the TRUST mechanism between EA Games’ ea.com or origin.com domains and their subdomains could be abused to manipulate the OAuth protocol implementation for full account take-over/exploitation”

In results, Researchers figured out that the EA games oAuth SSO implementation within several EA services such as answers.ea.com, help.ea.com, and accounts.ea.com.

“The SSO mechanism exchanges the user credentials (username & password) by unique SSO Token and this token can be used to authenticate any platform that belongs to EA network.”

So if the attacker steals the SSO Token by sending the specially crafted malicious link to victims, it gives them an active login session, eventually trigger the authentication to hijack the victim’s account.

Watch the demonstration about how an attacker hijacking the gamers live session to compromise their entire account and gain access to their sensitive data.

According to Oded Vanunu, Head of Products Vulnerability Research for Check Point, “EA’s Origin platform is hugely popular; and if left unpatched, these flaws would have enabled hackers to hijack and exploit millions of users’ accounts,”

This critical vulnerability not only provides access to the gamers account but it allows the attacker to purchase the virtual currency using the user’s credit card.

In order to avoid such attacks and protect from session hijacking, Check Point and CyberInt strongly advise users to enable two-factor authentication and only use the official website when downloading or purchasing games.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity course online to keep yourself updated.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

FBI Alerts Public to Scammers Posing as IC3 Officials in Fraud Scheme

The Federal Bureau of Investigation (FBI) has issued a warning regarding an emerging scam...

New ‘Waiting Thread Hijacking’ Malware Technique Evades Modern Security Measures

Security researchers have unveiled a new malware process injection technique dubbed "Waiting Thread Hijacking"...

EU’s GDPR Article 7 Poses New Challenges for Businesses To Secure AI-Generated Image Data

As businesses worldwide embrace digital transformation, the European Union’s General Data Protection Regulation (GDPR),...