uTorrent Windows Apps Contain Security Flaws That Let Attackers Control Your Computer, Fixes Coming

Advertisement
By Sumit Chakraborty | Updated: 22 February 2018 12:29 IST
Highlights
  • Google Project Zero researcher found out the critical bugs
  • Hackers can potentially download malware and access download history
  • Exploit affects all unpatched Windows versions of uTorrent

A Google Project Zero researcher has discovered critical bugs in two versions of the popular uTorrent app. With millions of daily users, uTorrent is considered one of the most widely used torrent clients. However, parent company BitTorrent was alerted to the serious security issue. Google researcher Tavis Ormandy has detailed several exploits in Windows versions of the software that lets attackers intrude into a user's computer.

Because it is a DNS rebinding issue, hackers can potentially execute remote code, download malware to the computer's startup folder, launch malware on reboot, access downloaded files, as well as peep at the user's download history, Ormandy said. While the exploit affects all unpatched versions, it primarily affects uTorrent Web, the newer version of the popular BitTorrent client, as it has a serious remote code execution bug, as per the Google researcher. The examples of exploits, as mentioned by Ormandy, include one for uTorrent Web, and two for uTorrent desktop.

Meanwhile, as per a TorrentFreak report, BitTorrent had rolled out a 'patch' in the latest Beta release and promises to fix the stable uTorrent client soon. Later, in an official statement, the company said, "Our fix is complete and is available in the most recent beta release (build 3.5.3.44352 released on 16 Feb 2018). This week, we will begin to deliver it to our installed base of users. All users will be updated with the fix automatically over the following days. The nature of the exploit is such that an attacker could craft a URL that would cause actions to trigger in the client without the user's consent (e.g. adding a torrent)."

Advertisement

However, Ormandy had expressed his displeasure with BitTorrent's response. He said, BitTorrent just added a second token to uTorrent Web which does not solve the issue. Further, he wrote, "I just fixed the exploit and verified it still works. I would recommend asking BitTorrent to resolve this issue if you're affected, and it works in the default configuration so you probably are. Sigh."

Advertisement

It is not clear if an attacker has made use of the exploits in the wild. However, it will only take one visit to a targeted website to trigger a hack. In order to stay safe, users can either disable uTorrent for now or upgrade to the latest Beta release. The uTorrent version 3.5.3.44352, is available for download and uTorrent Web users can update to the latest available build 0.12.0.502.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 SoC, Slim 5.99mm Profile
  2. Moto G67 Power 5G Launched in India With 7,000mAh Battery: See Price
  3. Lava Agni 4 Price Range, Features Leaked; Will Launch in These Colourways
  4. Samsung Galaxy S26 Ultra Spotted in Leaked Renders With Rounder Corners
  5. Apple's Low-Cost MacBook Launch Timeline, Price Leaked Ahead of Debut
  6. WhatsApp's Apple Watch App Is Finally Out: Check Features, Compatibility
  7. Realme UI 7.0 Launched With Light Glass Design, AI Features
  8. Moto G Play (2026), Moto G (2026) With Dimensity 6300 SoC Launched
  9. OnePlus Ace 6 Pro Max Configurations Leaked; May Feature Up to 16GB of RAM
  10. Southern Taurid Meteor Shower 2025 Promises Bright Fireballs in a Rare Swarm Year
  1. Moto G57 Power With 7,000mAh Battery Launched Alongside Moto G57: Price, Specifications
  2. Steam Deck Gets a Display-Off Low-Power Mode for Downloads Three Years After Launch
  3. Snapdragon 8 Elite Gen 6 Leak Hints at Two Variants Including 'Pro' Model
  4. Realme Will Try to Absorb Increased Cost of Components Ahead of Upcoming Product Launches, Executive Says
  5. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 Chipset, Slim 5.99mm Profile: Price, Specifications
  6. Researchers Unveil How Atomic Entanglement Enhances Light Bursts
  7. Lava Agni 4 Confirmed to Launch in Two Colourways; Tipster Leaks Price Range, Key Features
  8. Google Proposes Play Store Reforms in Settlement With Fortnite Maker Epic Games
  9. Scientists Recreate Cosmic ‘Fireballs’ in Lab to Solve Mystery of Missing Gamma Rays
  10. Realme UI 7.0 Launched With Light Glass Design, AI Notify Brief and AI Gaming Coach: See Eligible Phones, Beta Release Schedule
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.