Holy shit, Valve. Really? Nearly two years later and this is still exploitable.
Edit, further on:
> This is not the first time Valve has been slow to respond and fix reported vulnerabilities. In 2018, Motherboard reported that a security researcher found a bug in Steam that allowed hackers to take over victims' computers—a bug that had been present for 10 years. In 2019, Valve banned a security researcher from its bug bounty program, prompting him to publish the exploit publicly.
I'm pretty appalled by this.