People realize games are often used as attack vectors now, right?

Final Fantasy, old Japanese computers, Linux 🤓
People realize games are often used as attack vectors now, right?
Ah I saw a thing that said game dev doesn't need to take security into consideration. Everything else in the post was right, but I thought that was weird.
It was about balataro using a bunch of statements that are all executed quickly in lua.
tbh it's all a matter of risk and scope, but if a game goes online to either play with others or fetch updates or blog posts, or can run any file from other people (mods generally not included) they had better keep that risk in mind and adjust accordingly.
That would be most games now, really, unless they rely on an intermediary like steam to update.
iirc most games' updaters are separate code, for the most part, though. the updater doesn't give the game engine a network stack
I'm more talking about like, fetching raw HTML, over unsecured HTTP, and rendering that clientside