ZeroHour

CVE-2026-30612

mass

Remote code execution in Time4 Popcorn updater components (Windows, macOS, Android)

CVSS 3.1
9.8 critical
EPSS
<1%p23
Published
()
Modified
AI analysis

Time4 Popcorn, a free Popcorn Time-based streaming client, contains a download-of-code-without-integrity-check flaw (CWE-494) in its updater components: updater.exe on Windows and PT.updd on macOS. Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), a remote attacker can trigger the flaw over the network without credentials or user interaction, plausibly by delivering malicious code through the unverified update channel that these updaters download and execute. Successful exploitation yields arbitrary code execution on the victim machine with the application's privileges, enabling full compromise of the endpoint. All users running Time4 Popcorn for Windows up to 6.2.1.18, for macOS up to 6.2.1.17, and for Android up to 3.5.0.173 are affected. There is no public proof-of-concept, no CISA KEV listing, and EPSS is 0.3% (23rd percentile), so exploitation has not been observed and is considered unlikely in the next 30 days despite the critical 9.8 CVSS score.

What to do: Upgrade Windows clients to a version above 6.2.1.18, macOS clients above 6.2.1.17, and Android clients above 3.5.0.173 as soon as the vendor publishes fixed builds, since no fixed version numbers are included in this data. Until then, restrict the updater's network access to trusted, encrypted channels and be cautious of any unexpected update prompts from the app. Given the absence of public PoCs and in-the-wild exploitation, urgency is moderate, but the critical CVSS 9.8 rating warrants prompt patching of consumer endpoints.

Affected
Time4 Popcorn for Windows<= 6.2.1.18
Time4 Popcorn for macOS<= 6.2.1.17
Time4 Popcorn for Android<= 3.5.0.173
Estimated exposure
mass~1M+ cumulative consumer installs across Windows, macOS, and Android (no authoritative current active-install count) — The Popcorn Time streaming-client family, of which Time4 Popcorn is a prominent consumer-facing fork, historically reached millions of users, so cumulative installs across the three platforms likely exceed one million, though the number of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components

Weakness
CWE-494
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.