Researcher Disclosed BrokenPipe Steam Vulnerability

A privilege escalation flaw in the Steam Client Service remains unfixed following a March 2026 disclosure.

Updated on Oct. 4, 2026 in Cybersecurity

Bold flat-color editorial illustration of a single cracked stone archway on a deep red background, representing a security vulnerability.
Security researchers identified a privilege escalation vulnerability in the Steam Client Service, allowing unauthorized system-level access on Windows platforms. AI Illustration. Upload story photo >

Live Poll

Do you trust software companies to promptly disclose and fix security flaws in their products?

Security researcher KillaBoi publicly shared proof-of-concept code for the BrokenPipe vulnerability on September 15, 2026. The flaw allows local users on Windows to escalate privileges to NT AUTHORITY SYSTEM via the Steam Client Service.

Why it matters

The vulnerability permits standard users or existing malware to gain highest-level system permissions without requiring administrator passwords or UAC prompts. This risk is compounded by the lack of a public security advisory or fix from Valve.

Testing confirmed the privilege escalation flaw on Steam client version 10.96.30.42. The disclosure follows six months of silence since the initial report was submitted in March 2026.

The players

KillaBoi

The security researcher who discovered and disclosed the BrokenPipe vulnerability in the Steam client.

Valve

The developer and publisher of the Steam gaming platform and associated client software.

Vasily Kravets

A security researcher known for reporting prior privilege escalation vulnerabilities in the Steam platform.

The details

The vulnerability functions by exploiting communication channels between the Steam Client Service and ordinary user processes to execute code with SYSTEM-level permissions. A local user or existing malware can abuse this flaw to bypass standard account limitations on Windows 10 and 11.

Timeline

  1. 2019: Researcher Vasily Kravets previously identified similar escalation flaws.

  2. March 2026: KillaBoi submitted the initial vulnerability report to Valve.

  3. Mid-September 2026: Proof-of-concept code for the vulnerability was published.

  4. October 4, 2026: Reports confirmed no public security fix exists.

The Tech Race

This discovery follows a pattern set by the 2019 Steam privilege escalation vulnerabilities reported by Vasily Kravets. The incident highlights recurring security challenges in maintaining high-privilege background services within widely used desktop gaming clients.

Windows users running the Steam client may remain exposed to privilege escalation risks until an official software update is issued. Users are advised to monitor for client patches and exercise caution regarding unknown files or programs that could trigger local code execution.

The takeaway

Maintaining the security of background services remains a critical challenge for developers of complex desktop applications. Users should ensure their software is updated regularly to mitigate potential risks from unpatched vulnerabilities.

Further reading

For more information on digital security threats, visit our Cybersecurity section.

Source note: This article includes information reported by TalkEsport.

Live Poll

Do you trust software companies to promptly disclose and fix security flaws in their products?