Cyberpunk 2077's security vulnerability is now fixed

Cyberpunk
(Image credit: CD Projekt)

Update: CD Projekt says the security flaw should now be fixed, thanks to the new 1.12 hotfix.

CD Projekt Red is warning Cyberpunk 2077 players to be cautious when using mods, as a recently discovered vulnerability in a DLL file could be used to execute code on PCs and PlayStation 4 consoles running the game.

The issue came to light over the weekend thanks to Red Tools mod team member PixelRickyRick and redditor Romulus_Is_Here, who explained that "through the use of a mod or a crafted save game, malicious codes can be executed to take control of the PC by the creator of the save game/mod." The exploit was initially thought to be limited to the PC version of the game, but PixelRickyRick later confirmed that the PS4 version is vulnerable as well.

CD Projekt was made aware of the vulnerability a week ago, according to the post, but only acknowledged it today.

"A group of community members reached out to us to bring up an issue with the external DLL files the game uses," the studio said in a statement sent to Eurogamer. "This issue can be potentially used as part of a remote code execution on PCs. We appreciate their input and are working on fixing this as soon as possible. In the meantime, we advise everyone to refrain from using files obtained from unknown sources. Anyone who plans to use mods or custom saves for Cyberpunk 2077 should use caution until we release the aforementioned fix."

If you don't want to wait for that, the latest update to the Cyber Engine Tweaks mod, which includes "performance fixes, bug fixes, and fun hacks to play with," also addresses the vulnerability. I've reached out to CD Projekt to ask if there's a time frame for the official fix, and will update if I receive a reply.

TOPICS
Andy Chalk
US News Lead

Andy has been gaming on PCs from the very beginning, starting as a youngster with text adventures and primitive action games on a cassette-based TRS80. From there he graduated to the glory days of Sierra Online adventures and Microprose sims, ran a local BBS, learned how to build PCs, and developed a longstanding love of RPGs, immersive sims, and shooters. He began writing videogame news in 2007 for The Escapist and somehow managed to avoid getting fired until 2014, when he joined the storied ranks of PC Gamer. He covers all aspects of the industry, from new game announcements and patch notes to legal disputes, Twitch beefs, esports, and Henry Cavill. Lots of Henry Cavill.

Latest in RPG
No Rest for the Wicked Steam early access screenshots
No Rest for the Wicked developer Moon Studios is now 'fully independent' after acquiring the rights to the game from Take-Two
Project C4 teaser still
It's another day of Disco Elysium-related announcements trying to kneecap each other: Studio ZA/UM has put out a teaser for its first new game since 2019, and it's not Disco Elysium 2
Monster Hunter Wilds - a player yells in despair with their arms out, kneeling on the ground.
Some Monster Hunter Wilds players are skipping the endgame weapon grind because they just freaking hate how they look
Art of a woman smoking a cigarette on teal background wearing leather jacket, challenging the viewer.
After suing a Disco Elysium writer to prevent him from making his own game, a tech CEO who's allegedly banned from the Disco Elysium subreddit is trying to crowdfund a spiritual successor
Atelier Ryza's protagonist, Ryza, looks surprised as magic flares around her.
Japanese game producer argues that thick thighs on anime girls are a natural byproduct of economic recession
Monster Hunter Wilds official art
If you've captured them for a minute, monsters in Monster Hunter Wilds are legally allowed to leave
Latest in News
A masked man with an axe in the woods
Rebellion CEO seems kind of awed by major studios making massive videogames: 'How do you organize a game that has 2,000 people working on it?'
A young witch watering a smiling mushroom in a magic garden
Here's a roguelite dungeon crawler Steam reviewers call 'a botanical Diablo' and 'like Cult of the Lamb' except you manage a mystical garden
Destiny 2 Rite of the Nine: The Emissary, massive, ominously standing at the edge of a water basin.
Oops! Bungie rolled out Destiny 2's Rite of the Nine event three weeks early, and new loot is already dropping
Chatacabra from Monster Hunter Wilds
The latest Monster Hunter Wilds event quest gives piles of Armor Spheres for hunting a Chatacabra, making this a very bad week to be a frog in the Forbidden Lands
No Rest for the Wicked Steam early access screenshots
No Rest for the Wicked developer Moon Studios is now 'fully independent' after acquiring the rights to the game from Take-Two
A hunter posing with an absurd Blangonga outfit in Monster Hunter Wilds.
Attention, fashion hunters: There's a Monster Hunter Wilds mod to disable all those obnoxious glowing buff effects that distract from your fits