Skip to main content

Steam community site suffers profile vulnerability but Valve makes quick fix

steam community site suffers profile vulnerability steamdev
Image used with permission by copyright holder
If you’re any kind of PC gamer, then you likely frequent Valve’s Steam service to procure at least some of your games. And if you’re a Steam customer, then you likely spend some time on Steam’s community site — and until just recently, that might not have been the safest place to be.

It appears that the Steam community site suffered from an exploit involving user profiles that could redirect users to alternate pages and download PHP code, Ars Technica reports. Valve was able to fix the exploit soon after it was announced, but not before a number of people had created profiles that exploited the vulnerability.

Recommended Videos

The exploit was first identified on the Steam subreddit, described as such:

Please enable Javascript to view this content

“Currently, there is a risk (i.e. phishing, malicious script execution, etc.) involved when viewing or simply opening PROFILE pages of other steam users as well as your OWN activity feed (both desktop and mobile versions on all browsers including steam browser/chromium). I would advise against viewing suspicious profiles until further notice and disable JavaScript in your browser options. Do NOT click suspicious (real) steam profile links and Disable JavaScript on Browser. Appropriate information has been forward to Valve and this issue should be resolved soon, sorry for any inconvenience.”

Since that post was first created, Valve was able to fix the exploit and was able to classify Steam profiles and activity feeds as safe to visit. The exploit was subsequently explained in full in a follow-up Reddit post. Steam has more than 125 million users and any exploit on the Steam community site could have serious repercussions.

Apparently, the chances of long-term problems caused by the vulnerability were slim, but nevertheless, anyone who might have suffered from the exploit while it was live is recommended to turn on two-factor authentication, keep up with Valve’s official channels for more information, and, of course, change their Steam password.

Mark Coppock
Mark Coppock is a Freelance Writer at Digital Trends covering primarily laptop and other computing technologies. He has…
Surprise Steam agreement update says you can now sue Valve directly
The Zotac Zone handheld gaming console running Steam.

Many players -- including me -- got a bit of a jump scare Thursday evening while playing games on Steam in the form of a pop-up that said Valve updated the Steam Subscriber Agreement. Like most people, I clicked the checkbox, accepted the changes, and tried to go back to my game.

Looking back, though, this update is kind of a big deal, as Valve has removed its forced arbitration clause. This means that it's now easier than ever to sue the company, and the changes have been implemented immediately.

Read more
Valve has made sharing games on Steam easier than ever
A Steam library filled with custom artwork.

Steam Families is now available to all users, making it easier than ever to share your games library and monitor your child's activity.

The PC gaming platform has had family features for a while, going back to Steam Family Sharing and parental controls like Family View. But Steam Families -- announced in beta in May --  puts them in one hub. It officially went live on Wednesday, and since it's now the weekend, this is a great time to start sharing games.

Read more
Steam Deck OLED fixes the worst part of Valve’s handheld
Valve's Steam Deck OLED.

Valve just announced the Steam Deck OLED, which is an updated model of the original Steam Deck featuring a new OLED screen. Unlike the previous model, Valve is only selling two versions of the Steam Deck OLED, one with 512GB of storage and another with 1TB of storage for $550 and $650, respectively.

Although the OLED screen is the star of the show, Valve is making some upgrades elsewhere, too. The new design is now based on a 6nm APU, as opposed to the 7nm APU in the previous model, and it supports Wi-Fi 6E. The previous model only supported Wi-Fi 5.

Read more