CVE-2026-30612
massRemote code execution in Time4 Popcorn updater components (Windows, macOS, Android)
Time4 Popcorn, a free Popcorn Time-based streaming client, contains a download-of-code-without-integrity-check flaw (CWE-494) in its updater components: updater.exe on Windows and PT.updd on macOS. Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), a remote attacker can trigger the flaw over the network without credentials or user interaction, plausibly by delivering malicious code through the unverified update channel that these updaters download and execute. Successful exploitation yields arbitrary code execution on the victim machine with the application's privileges, enabling full compromise of the endpoint. All users running Time4 Popcorn for Windows up to 6.2.1.18, for macOS up to 6.2.1.17, and for Android up to 3.5.0.173 are affected. There is no public proof-of-concept, no CISA KEV listing, and EPSS is 0.3% (23rd percentile), so exploitation has not been observed and is considered unlikely in the next 30 days despite the critical 9.8 CVSS score.
What to do: Upgrade Windows clients to a version above 6.2.1.18, macOS clients above 6.2.1.17, and Android clients above 3.5.0.173 as soon as the vendor publishes fixed builds, since no fixed version numbers are included in this data. Until then, restrict the updater's network access to trusted, encrypted channels and be cautious of any unexpected update prompts from the app. Given the absence of public PoCs and in-the-wild exploitation, urgency is moderate, but the critical CVSS 9.8 rating warrants prompt patching of consumer endpoints.
| Time4 Popcorn for Windows | <= 6.2.1.18 |
| Time4 Popcorn for macOS | <= 6.2.1.17 |
| Time4 Popcorn for Android | <= 3.5.0.173 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components
- Weakness
- CWE-494
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.