Source: Activision took down Call of Duty: WWII after hackers exploited a flaw in a specific PC version, which led to some players having their computers hacked
Campaign Mode: Incident Commander — Multiplayer Mode: Everyone's On Call — DLC: Zero-Day at Dawn [embedded post] Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: We confirmed that Activision took a version of Call of Duty: WWII offline because hackers were taking over players' PCs. — Sources tell us that the issue was a bug that had been patched in other versions of the game, but not on the one for Microsoft Store and Game Pass, which are still offline. Forums: r/technology : Call of Duty: WW2 pulled from PC following reports of remote code exploit trolling players with ‘Notepad pop-ups, PC shutdowns’ and desktop wallpaper of a lawyer Msmash / Slashdot : Activision Took Down Call of Duty Game After PC Players Hacked
Context & Ripple Effects
This is the latest security incident involving older Call of Duty PC releases: Activision previously shut down multiplayer after a worm spread through lobbies in an older Call of Duty title. The recurring issue is not merely cheating, but game-client vulnerabilities that can affect players’ machines.
The reported gap is platform-specific: a fix present in other PC versions was not applied to the Microsoft Store/Game Pass build. That makes release and patch parity across PC storefronts a security-operations issue, not just a distribution detail.
First-order effects
- Activision has taken the affected Microsoft Store/Game Pass version of Call of Duty: WWII offline, interrupting access for players on that build while the exploit is addressed.
- Players on the vulnerable version face an immediate endpoint-security risk; the reported behavior goes beyond in-game disruption to unauthorized control of their PCs.
Second-order effects
- Activision and platform partners must identify why the patch did not reach this distribution channel and verify whether other storefront-specific builds have similar update gaps.
- The incident reinforces the cost of treating PC-game exploits as ordinary cheating. Activision had already warned that a purported Warzone cheat could be malware capable of taking over a player’s machine, but this case originates in the game version itself.
Third-order effects
- If storefront builds continue to diverge in patch status, publishers will need stronger release-parity controls and faster mechanisms to disable or update vulnerable legacy clients across channels.
- Older live-service games may increasingly be judged by the security burden of keeping online PC components available, making selective shutdowns more likely when maintainers cannot rapidly close serious flaws.
The trend: PC game security is shifting from anti-cheat enforcement toward lifecycle management of vulnerable clients across fragmented storefront and subscription builds.