CriticalClaim

@criticalclaim.bsky.social

Sometimes artist, sometimes video editor, sometimes streamer, mostly fool. ¯\_(ツ)_/¯ https://www.youtube.com/channel/UCzBGR9bwP_Nb3fguxzfeBEg https://www.twitch.tv/criticalclaim

I am once more doing my part with VAs for Palestine where our efforts, god willing, shall be put to good use in aiding the Palestinian people in their time of great need. Come and score some vo comissions all for the price of some sweet, sweet charity. Come one, Come all!

Kawiria | VA🎙️@kjcreed.bsky.social · 24h ago

Over 120 VOICE ACTORS FOR PALESTINE. Let's raise as much support as possible for @opolivebranch.bsky.social! GO GO GO Requests OPEN: ‼️NOW‼️ Requests CLOSE: Oct 24 Form: forms.gle/zTij7kZtoeT7... #VoiceActorsforPalestine

Okay a tiny thread because people are going to freak out: This exploit in particular takes advantage of a special command that renders images (via attribute escape). If you have an overlay that processes images (most don't) then yes, this is your problem. Overlay must explicitly create img DOM.

A picture of the exploit, using a command that explicitly includes an image file extension, but also would escape out of the src attribute of an image such than an onerror attribute can be added to the img tag. This onerror attribute can run explicit javascript immediately.

Default behavior for most chat widgets is if you have an image it will not attempt to modify image links into actual HTML image tags. Your overlay/overlay service must explicitly be doing this for you.