Description
An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components
Published: 2026-08-27
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An update mechanism in Time4 Popcorn for Windows, MacOS, and Android allows a remote attacker to run arbitrary code on the target system. The flaw resides in the updater executable (updater.exe on Windows, PT.updd on MacOS) and can be triggered by an attacker who can cause the updater to execute without user intervention. If exploited, the attacker could gain full control of the affected machine, install malicious software, or exfiltrate data, leading to a complete compromise of confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects Time4 Popcorn for Windows versions 6.2.1.18 and earlier, Time4Popcorn for MacOS up to 6.2.1.17, and Time4Popcorn for Android through 3.5.0.173. Users running these specific releases should verify their version and be aware that any omitted patches create a risk vector.

Risk and Exploitability

No CVSS score is publicly available, and the EPSS score is not listed, suggesting limited public exploitation data at this time. The vulnerability is not in the CISA KEV catalog. However, the lack of a known exploit does not mitigate the risk, as the flaw allows remote code execution without user interaction, making it highly attractive to adversaries. Attackers could leverage the updater to spawn arbitrary code, potentially compromising the device or network.

Generated by OpenCVE AI on August 28, 2026 at 06:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Time4 Popcorn update that removes the vulnerable updater (Windows 6.2.1.19+, MacOS 6.2.1.18+, Android 3.5.0.174+).
  • If immediate update is not possible, disable or block the updater executable (updater.exe/PT.updd) using firewall rules or antivirus exclusions to prevent execution.
  • Monitor system activity for unexpected updater execution and investigate any anomalous behavior promptly.

Generated by OpenCVE AI on August 28, 2026 at 06:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Vulnerable Updater in Time4 Popcorn Software
Weaknesses CWE-94

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-27T16:59:32.184Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-30612

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T20:17:33.780

Modified: 2026-08-27T20:17:33.780

Link: CVE-2026-30612

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T06:15:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')