A security researcher discovered a vulnerability in the Lua implementation of the game Factorio, which allowed a malicious server to obtain arbitrary execution on clients. The vulnerability was patched in Factorio version 1.1.101. The researcher explains the details of the vulnerability, including how it was possible to execute malicious bytecode and create fake objects. The vulnerability was due to a combination of factors, including the use of deterministic lockstep in the game's multiplayer mode and the ability to execute Lua code on clients.