If I understand correctly their PDF, this vulnerability is bullshit. In order to be exploited, user needs to click on youtube video title link in steam browser and then click on a malicous steam:// ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results
Feedback