CVE-2026-107448: Low severity Wizards of the Coast Magic: The Gathering Arena vulnerability
Magic: The Gathering Arena (Windows/Steam client; 2026.59.30.12801.127931.6 and certain later 2026.60.x builds) passes a server-supplied URL from a home-screen carousel GoToExternalUrl action directly to the Windows shell via Application.OpenURL/ShellExecuteW without validating the URI scheme or domain. A hypothetical attacker able to control the carousel content delivered to clients can cause arbitrary registered URI-scheme handlers to be invoked on client hosts with no user interaction. For example, one might expect that the carousel content only has https: URIs, not ms-calculator: URIs.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Windows/Steam client users running version 2026.59.30.12801.127931.6 or certain later 2026.60.x builds may be exposed if they receive attacker-controlled home-screen carousel content.
What does an attacker need to exploit it?
An attacker must be able to control the carousel content delivered to clients. No client-side privileges or user interaction are required once such content is delivered.
What can exploitation do on an affected client?
It can invoke arbitrary URI-scheme handlers registered on Windows through Application.OpenURL/ShellExecuteW. The provided example is an ms-calculator: URI rather than an expected https: URI.
Are normal carousel URLs validated before being opened?
No URI scheme or domain validation is performed before the server-supplied URL is passed to the Windows shell. The description indicates carousel content is expected to contain https: URIs, but other registered schemes can be invoked.