External risk intelligence

Time4Popcorn Remote Code Execution via Updater Component

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-30612

The vulnerability affects client-side desktop and mobile applications (Time4Popcorn). These are end-user software products, not internet-facing infrastructure, gateways, or public-facing services. Exploitation requires the victim to run the application, making public network exposure of the vulnerable component unlikely in typical deployment contexts.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Time4Popcorn software that could allow remote attackers to execute arbitrary code. This issue affects Windows, macOS, and Android versions of the application through their update components. The primary concern is to confirm if this software is used within the organization and if so, assess potential exposure.

  • Code execution flaw in update components.
  • Affects user-installed applications, not infrastructure.
  • Confirm usage and assess any relevant exposure.

Attack Path

How an attacker could exploit the issue

An attacker could compromise a user's system by tricking them into downloading a malicious update for the Time4 Popcorn application. If a user installs this fake update, it could allow the attacker to run their own code on the user's computer.

  • Requires user to download malicious update.
  • Triggered by installing fake updater.
  • Allows arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow a remote attacker to execute arbitrary code on a user's device by exploiting the application's updater component. This could occur when the application checks for or downloads updates, potentially leading to the compromise of the affected system.

  • User's computer or mobile device.
  • Via the application's update mechanism.
  • Compromise of system and user data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Time4Popcorn client applications on Windows, macOS, and Android. Ownership likely resides with the end-user device owners and the teams supporting the devices, possibly including desktop support or mobile device management. The first practical step is to identify users running the affected application and assess the potential for exploitation given the need for user interaction.

  • End-user device owners should be accountable.
  • Verify application usage and user exposure.
  • Plan for user-informed remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Time4Popcorn?

Time4Popcorn is a cross-platform application used to stream media content. It is designed as a client-side program for Windows, macOS, and Android devices, allowing users to access and play video files directly on their personal computers or mobile hardware.

What does CWE-494 mean for CVE-2026-30612?

CWE-494 refers to a vulnerability where software downloads code or data without sufficient verification of its origin or integrity. In this CVE, the application's update process fails to properly validate the files it retrieves, creating a weakness that could allow an attacker to substitute legitimate updates with malicious code.

How is this vulnerability triggered?

The flaw is triggered when the application interacts with its update mechanism to fetch new files. This does not happen automatically by just having the app installed; rather, an attacker must successfully trick the software into downloading and processing a malicious update package, which the system then executes.

Is this a risk to my servers, according to Halo Surface Signal?

Halo Surface Signal indicates this risk is very unlikely for internet-facing infrastructure. Because Time4Popcorn is an end-user desktop or mobile application, it is not a server-side service or gateway. The threat is confined to individual client devices where users actively run the software, rather than network-exposed systems.

What should I do if I run this software?

Start by identifying all devices where Time4Popcorn is installed. Since the vulnerability requires user interaction to execute malicious updates, evaluate the necessity of the application on your systems. If it is not required, removing it is the most effective way to eliminate the risk. Otherwise, monitor official vendor channels for authorized software updates.

References