0x01 Introduction Over the past month or so, I’ve spent quite a bit of time reading and experimenting with custom URI schemes. As the last post on this blog clearly demonstrated, a poorly implemented custom URI can have a number of security concerns. When I say “a number”, it’s because I’m about to bring a few more to light, using EA’s Origin Client as our crash test dummy. TL;DR: Another Origin RCE, unrelated to CVE-2019-11354.