Overwolf provides a gaming-overlay and modding platform that integrates deeply into popular game environments, with its vulnerability footprint centered on the core platform product. The observed weakness classes reflect the software's role as an in-game injection and content-delivery layer: uncontrolled search paths, improper link resolution, and cross-site scripting issues recur across its disclosures and align with the security demands of hooking into third-party games and rendering user-generated content. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Overwolf over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33501CRITICAL Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL. | Jul 19, 2021 | 9.6 | 34 | NO | NO |
CVE-2020-15932HIGH Overwolf before 0.149.2.30 mishandles Symbolic Links during updates, causing elevation of privileges. | Jul 24, 2020 | 8.8 | 30 | NO | NO |
CVE-2020-25214HIGH In the client in Overwolf 0.149.2.30, a channel can be accessed or influenced by an actor that is not an endpoint. | Oct 16, 2020 | 8.1 | 26 | NO | NO |
CVE-2021-20726HIGH Untrusted search path vulnerability in The Installer of Overwolf 2.168.0.n and earlier allows an attacker to gain privileges and execute arbitrary code with the privilege of the us | May 24, 2021 | 7.8 | 24 | NO | NO |
CVE-2024-7834HIGH A local privilege escalation is caused by Overwolf
loading and executing certain dynamic link library files from a user-writeable
folder in SYSTEM context on launch. This allows an | Sep 4, 2024 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Overwolf.
Media articles that mention a CVE ID that affects a product developed by Overwolf — matched by CVE ID, not by vendor name.