CVE-2026-30612: Time4Popcorn Time4 Popcorn for Windows vulnerability
An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Time4 Popcorn for Windowsto a version that resolves this vulnerability.Fixed in 6.2.1.18 - Upgrade
Upgrade
Time4Popcorn for MacOSto a version that resolves this vulnerability.Fixed in 6.2.1.17 - Upgrade
Upgrade
Time4Popcorn for Androidto a version that resolves this vulnerability.Fixed in 3.5.0.173
Event History
Frequently Asked Questions
Which installations are within the affected version ranges?
Time4 Popcorn for Windows versions up to and including 6.2.1.18, Time4Popcorn for macOS versions up to and including 6.2.1.17, and Time4Popcorn for Android versions up to and including 3.5.0.173 are identified as affected.
Which components are implicated in the reported code-execution issue?
The description identifies updater.exe on Windows and PT.updd on macOS as the affected components. No Android-specific component is named.
What attacker access is described as necessary?
The issue is described as remotely exploitable and capable of allowing arbitrary code execution. The provided data does not specify authentication, user interaction, network position, or other preconditions.