URL Handling Vulnerability in Magic: The Gathering Arena by Wizards of the Coast
CVE-2026-107448
3.4LOW
What is CVE-2026-107448?
The vulnerability in Magic: The Gathering Arena allows a server-supplied URL from the home-screen carousel to be executed via the Windows shell without proper validation. An attacker controlling carousel content could potentially invoke arbitrary URI-scheme handlers on the client machines, leading to security risks as users may inadvertently run harmful URIs that should not be executed without interaction.
Affected Version(s)
Magic: The Gathering Arena Windows 2026.59.30.12801.127931.6
