In a dramatic move to protect its player base, Activision has temporarily removed Call of Duty: WWII from the Microsoft Store and Xbox PC Game Pass following reports that the gameโs PC version harbors a serious remote code execution (RCE) vulnerability. This flaw reportedly allowed hackers to take control of players’ computers mid-match, installing malware, crashing systems, and even defacing desktop environments.
โ ๏ธ What Happened?
- The Microsoft Store and Game Pass editions of CoD: WWII were released in June 2025.
- Within days, PC gamers began reporting freezing gameplay, command prompt pop-ups, forced shutdowns, and even desktop backgrounds replaced with provocative imagesโand a legal warningโall indicating a remote hack.
- Notably, a streamer named Wrioh publicly demonstrated their game freezing before hackers appeared to initiate a full system compromise.

๐ป How the Hack Worked
Researchers have confirmed that this was not a cheat exploit but a dangerous RCE vulnerability, allowing attackers to run malicious code on PCs through the gameโs client.
- The Microsoft Store/Game Pass version used outdated code that had not been patched, making it more vulnerable than the Steam or Battle.net versions.
- Some victims experienced desktop-level breachesโsystems were compromised during live gameplay, triggering malware installs or abrupt shutdowns .
๐ Activisionโs Immediate Action
In response to the threat, Activision took the PC version offline, stating it was doing so “while we investigate reports of an issue”.
- A Microsoft-owned source told TechCrunch that the shutdown was specifically triggered by the hacking incidents.
- The game remains playable via Steam and console platforms, which use patched versions.

๐ก๏ธ What Players Should Do
- Avoid downloading or playing Call of Duty: WWII on PC through Game Pass/Microsoft Store until itโs restored securely.
- Verify your version: Steam and console editions remain safe, as they’ve already received critical security updates.
- Watch for updates: Activision has not offered a timeline for the gameโs return but indicates a fix is in development.
๐ง Bigger Implications
This incident amplifies growing concerns about legacy game security, especially when older titles join modern distribution platforms using outdated builds. It also serves as a stark reminder of the powerfulโand riskyโreach games can have when they enable remote code execution.
