CVE-2026-30612

Time4Popcorn · Time4Popcorn

Time4Popcorn is vulnerable to remote code execution in Windows, MacOS, and Android versions due to flaws in the application updater components.

Executive summary

A critical remote code execution vulnerability in Time4Popcorn allows unauthenticated attackers to compromise affected Windows, MacOS, and Android systems.

Vulnerability

This vulnerability involves an insecure implementation within the update mechanisms (specifically updater.exe and PT.updd), which permits an unauthenticated remote attacker to achieve arbitrary code execution on the host system.

Business impact

The ability for an unauthenticated attacker to execute arbitrary code represents a total compromise of the affected system. Given the CVSS score of 9.8, this vulnerability poses an extreme risk, potentially leading to full data exfiltration, installation of persistent backdoors, and complete loss of system integrity.

Remediation

Immediate Action: Discontinue use of the affected Time4Popcorn software until a secure update is released by the vendor, as no patch is currently available.

Proactive Monitoring: Monitor network traffic for suspicious outbound connections originating from application update processes and audit endpoints for unauthorized changes to system binaries.

Compensating Controls: Restrict network access to untrusted update servers via firewall rules and ensure that endpoint security software is configured to block unauthorized execution attempts from updater components.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability presents a severe risk due to the potential for unauthenticated remote code execution. Because no patch is currently provided, organizations should treat this as a high-priority threat and consider removing the software from production environments to prevent compromise.

Sources