Heap-Based Buffer Overflow in Konami's Metal Gear Online 3 Affecting Player Management
CVE-2026-19874

Currently unrated

Key Information:

Vendor

Konami

Vendor
CVE Published:
24 August 2026

What is CVE-2026-19874?

A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3 due to improper validation of lobby data fields related to kicked players. The affected function processes kicked player identifiers without checking that the count of identifiers does not exceed the system's predefined limits. By manipulating the data sent to the function, an attacker can force the game to write beyond the allocated memory for the kicked player IDs. This not only corrupts memory but may also allow the attacker to alter crucial structures responsible for game events, leading to potential control-flow hijacking and arbitrary code execution within the game's process.

Affected Version(s)

Metal Gear Online 3 1.1.2.8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.