To access material, start machines and answer questions login.
MECCHA CHAMELEON is a multiplayer hide-and-seek game built around one simple idea: blend into the environment and try not to get caught.
Players can camouflage themselves against objects and scenery around the map, turning ordinary parts of the environment into potential hiding spots. The game quickly exploded in popularity, with players finding increasingly ridiculous places to hide and creating their own environments to keep matches feeling different.
Alongside the maps included with the game, MECCHA CHAMELEON supports community-created custom maps. These maps can be created by players and distributed through the Steam Workshop, allowing others to download and play entirely new environments.
Custom maps are a huge part of what makes games like MECCHA CHAMELEON interesting. Instead of being limited to content shipped by the developers, the community can build new levels and experiences for everyone else to play.
The way maps reach players matters here. When you join a lobby, the host picks the map and everyone else is prompted to download it before the match can begin. Joining a public game therefore means loading content built by somebody you have never met, and that content runs inside the game on your own machine.
This raises an important question: How much control should a custom map actually have?
MECCHA CHAMELEON had already suffered a remote code execution bug triggered by loading a map, documented here (opens in new tab) and patched at the time. That fix closed one route, but it did not answer whether others remained.
In September 2026, Robbe Van Roey of Aikido Security (opens in new tab) disclosed a second one. A community-created map could reach an exposed Unreal Engine audio function and use it to write attacker-controlled files anywhere on a player's system, leading to code execution the next time that player signed in.
- Affected versions: all versions of MECCHA CHAMELEON before 4.0.0
- Patched version: 4.0.0, released August 20, 2026, installed automatically before launch
- Attack vector: malicious custom map distributed through the Steam Workshop
- Impact: arbitrary file write leading to delayed remote code execution
Delayed: Nothing visible happens when the malicious map loads. The file is written quietly and waits. Execution arrives at the victim's next login, long after the match has ended, which is what makes this worth investigating from an analyst's seat later in the room.
What Will We Do?
In this room, we will explore what makes MECCHA CHAMELEON custom maps more powerful than they initially appear, break down the attack chain that made the vulnerability possible, and investigate the evidence it could leave behind on a compromised Windows system.
- Understand how malicious MECCHA CHAMELEON custom maps can lead to remote code execution.
- Conduct a forensic investigation of a compromised machine and identify artifacts related to the attack.
- Identify key indicators of compromise and understand how the vulnerability was mitigated.
I've learned about MECCHA CHAMELEON and I'm ready to continue!
Ready to learn Cyber Security?
The Chameleon Escape room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in
