CVE-2026-30612
Time4Popcorn · Time4Popcorn
Time4Popcorn is vulnerable to remote code execution in Windows, MacOS, and Android versions due to flaws in the application updater components.
Executive summary
A critical remote code execution vulnerability in Time4Popcorn allows unauthenticated attackers to compromise affected Windows, MacOS, and Android systems.
Vulnerability
This vulnerability involves an insecure implementation within the update mechanisms (specifically updater.exe and PT.updd), which permits an unauthenticated remote attacker to achieve arbitrary code execution on the host system.
Business impact
The ability for an unauthenticated attacker to execute arbitrary code represents a total compromise of the affected system. Given the CVSS score of 9.8, this vulnerability poses an extreme risk, potentially leading to full data exfiltration, installation of persistent backdoors, and complete loss of system integrity.
Remediation
Immediate Action: Discontinue use of the affected Time4Popcorn software until a secure update is released by the vendor, as no patch is currently available.
Proactive Monitoring: Monitor network traffic for suspicious outbound connections originating from application update processes and audit endpoints for unauthorized changes to system binaries.
Compensating Controls: Restrict network access to untrusted update servers via firewall rules and ensure that endpoint security software is configured to block unauthorized execution attempts from updater components.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a severe risk due to the potential for unauthenticated remote code execution. Because no patch is currently provided, organizations should treat this as a high-priority threat and consider removing the software from production environments to prevent compromise.