mannefriedrich: Cyberpunk 2077 is now at
v1.12 (was
v1.11) - seemingly everywhere else but on GOG, that is.
This update addresses the vulnerability that could be used as part of remote code execution (including save files):
- Fixed a buffer overrun issue.
- Removed/replaced non-ASLR DLLs.
mannefriedrich: No offline installer(s) for patching/updating, as of yet.
Sounds like a critical bug in the game.
If you can't update, some ways to mitigate this flaw:
* Don't load save files you don't trust. In particular, it's probably only a good idea to load saves that you made while playing the game.
* Don't let the game connect to servers or other devices. If possible, cut the game off from the internet, or disconnect your computer entirely while playing the game. (You might want to consider starting the game with Galaxy not running for the time being.)
* When you can update, do so as soon as possible.
Edit: Having read later posts, might want to disable cloud saving if you don't have the update, just in case GOG's server gets hacked and saves replaced with malicious ones.