CVE-2021-24030

CRITICAL

Facebook Gameroom <1.26.0 - Code Injection

Title source: llm

Description

The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the executable. That allows a malicious URL to cause code execution. This issue affects versions prior to v1.26.0.

Scores

CVSS v3 9.8
EPSS 0.0116
EPSS Percentile 78.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-88
Status published

Affected Products (1)

facebook/gameroom < 1.26.0

Timeline

Published Mar 10, 2021
Tracked Since Feb 18, 2026