Executive brief
Time4 Popcorn is a media streaming application available on Windows, macOS, and Android. A vulnerability in the application's updater component allows a remote attacker to execute arbitrary code on a user's device, potentially leading to complete system compromise, data theft, or installation of malware.
Technical details
The vulnerability exists in the updater mechanism of Time4 Popcorn (updater.exe on Windows, PT.updd on macOS, and the Android updater component). A remote attacker can exploit this flaw to execute arbitrary code without requiring authentication or user interaction beyond running the application. The attack is delivered through the update mechanism, making it difficult for users to avoid. No patch status is mentioned in the available advisory information.
Affected products
- Time4 Popcorn Windows <= 6.2.1.18
- Time4 Popcorn macOS <= 6.2.1.17
- Time4 Popcorn Android <= 3.5.0.173
Timeline
- 2026-08-27: disclosed: CVE-2026-30612 published