Researcher Disclosed BrokenPipe Steam Vulnerability
A privilege escalation flaw in the Steam Client Service remains unfixed following a March 2026 disclosure.
Updated on Oct. 4, 2026 in Cybersecurity

Live Poll
Do you trust software companies to promptly disclose and fix security flaws in their products?
Security researcher KillaBoi publicly shared proof-of-concept code for the BrokenPipe vulnerability on September 15, 2026. The flaw allows local users on Windows to escalate privileges to NT AUTHORITY SYSTEM via the Steam Client Service.
Why it matters
The vulnerability permits standard users or existing malware to gain highest-level system permissions without requiring administrator passwords or UAC prompts. This risk is compounded by the lack of a public security advisory or fix from Valve.
Testing confirmed the privilege escalation flaw on Steam client version 10.96.30.42. The disclosure follows six months of silence since the initial report was submitted in March 2026.
The players
KillaBoi
The security researcher who discovered and disclosed the BrokenPipe vulnerability in the Steam client.
Valve
The developer and publisher of the Steam gaming platform and associated client software.
Vasily Kravets
A security researcher known for reporting prior privilege escalation vulnerabilities in the Steam platform.
The details
The vulnerability functions by exploiting communication channels between the Steam Client Service and ordinary user processes to execute code with SYSTEM-level permissions. A local user or existing malware can abuse this flaw to bypass standard account limitations on Windows 10 and 11.
Timeline
2019: Researcher Vasily Kravets previously identified similar escalation flaws.
March 2026: KillaBoi submitted the initial vulnerability report to Valve.
Mid-September 2026: Proof-of-concept code for the vulnerability was published.
October 4, 2026: Reports confirmed no public security fix exists.
The Tech Race
This discovery follows a pattern set by the 2019 Steam privilege escalation vulnerabilities reported by Vasily Kravets. The incident highlights recurring security challenges in maintaining high-privilege background services within widely used desktop gaming clients.
Windows users running the Steam client may remain exposed to privilege escalation risks until an official software update is issued. Users are advised to monitor for client patches and exercise caution regarding unknown files or programs that could trigger local code execution.
The takeaway
Maintaining the security of background services remains a critical challenge for developers of complex desktop applications. Users should ensure their software is updated regularly to mitigate potential risks from unpatched vulnerabilities.
Further reading
For more information on digital security threats, visit our Cybersecurity section.
Source note: This article includes information reported by TalkEsport.
Live Poll
Do you trust software companies to promptly disclose and fix security flaws in their products?







