Overview
- The Xbox PC App (Microsoft Store) release was pulled on July 5 following reports of a remote code execution vulnerability affecting Game Pass users.
- Players shared clips of hijacked PCs showing Notepad pop-ups, forced shutdowns and wallpaper swaps to pornographic or lawyer images.
- White hat groups including VX-Underground warned attackers could leverage the exploit to install information-stealing malware, remote administration tools or ransomware.
- Activision’s only public statement confirmed the game was taken offline to investigate an “issue,” with no timeline provided for its return.
- The incident highlights security challenges when unpatched legacy titles join subscription services, underscoring the need for thorough vulnerability reviews.