Valve fixes Steam security exploit

The vulnerability came to light earlier today.

A warning went up on the Steam subreddit earlier today cautioning Steam users—so, pretty much all of us—to avoid opening profile pages of other users, and also their own activity feeds. The message is intentionally vague to help avoid spreading details about the exploit and how to use it, but it was posted by a subreddit moderator, while another mod says he's "investigated and created proofs of concept for this exploit." 

"Currently, there is a risk (i.e. phishing, malicious script execution, etc.) involved when viewing or simply opening PROFILE pages of other steam users as well as your OWN activity feed (both desktop and mobile versions on all browsers including steam browser/chromium)," the warning says. "I would advise against viewing suspicious profiles until further notice and disable JavaScript in your browser options. Do NOT click suspicious (real) steam profile links and Disable JavaScript on Browser." 

A Valve rep said that a fix has now—as of about 12:05 pm ET—been published, so the problem should be taken care of. If you think you were caught by the exploit before the fix went live, the message says you should change your Steam password, enable the mobile authenticator (which you really should be using anyway) or, if you already use it, go into the settings and de-authorize any other computers on Steam Guard, and then restart your modem or change your IP. A full scan of your system with a malware/anti-virus scanner probably wouldn't hurt either. 

Details of the exploit, which we can talk about now that it's been fixed, are available here.

Update: The post initially warned that a client update was required. It was in fact an issue with the Steam website.

Image credit: DiglidiDudeNG