Video Subtitle Files for Media Players Can Be Used to Take Control of Any Device: Report

Advertisement
By Ketan Pratap | Updated: 25 May 2017 11:57 IST
Highlights
  • Check Point researchers discovered the malicious subtitles
  • Researchers found popular media players like VLC and other infected
  • Fixed version for VLC, Kodi, Popcorn-Time and strem.io available
Video Subtitle Files for Media Players Can Be Used to Take Control of Any Device: Report

Researchers have claimed that popular media players are vulnerable to malicious subtitles files that could allow attackers to take control of any type of device. The researchers estimate that roughly 200 million video players and online streamers are currently vulnerable to such an attack.

The researchers at Check Point say that the malicious subtitle files once downloaded for a media player use could help attackers "complete control over any type of device" via vulnerabilities found in many popular streaming platforms including VLC, Kodi, Popcorn-Time and strem.io.

Check Point researchers further explain, "Our research reveals a new possible attack vector, using a completely overlooked technique in which the cyberattack is delivered when movie subtitles are loaded by the user's media player. These subtitles repositories are, in practice, treated as a trusted source by the user or media player; our research also reveals that those repositories can be manipulated and be made to award the attacker's malicious subtitles a high score, which results in those specific subtitles being served to the user. This method requires little or no deliberate action on the part of the user, making it all the more dangerous."

Unlike traditional attacks, movie subtitles is usually seen as a benign text file by the system which means antivirus software, and other security solutions vet them without trying to assess their real nature, leaving millions of users exposed to this risk.

Advertisement

Once the attacker takes control of the victim's device whether it is a computer, a smart TV, or a mobile device, the potential damage the attacker can inflict is endless, ranging anywhere from stealing sensitive information, installing ransomware, mass Denial of Service attacks, and much more.

Check Point researchers tested and found vulnerabilities in four popular media players like VLC, Kodi, Popcorn Time and Stremio. The media players have received patches to avoid the attack by malicious subtitles, and users can download the fixes via the Check Point site.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 14 5G Series Teased to Launch in India Soon
  2. Vivo Y400 Pro 5G With 5,500mAh Battery Launched in India: Price, Features
  3. OTT Releases This Week: Ground Zero, Detective Sherdil, Found S2, and More
  4. Vivo Y400 Pro 5G India Launch Today: All You Need to Know
  5. Samsung Galaxy M36 5G India Launch Date and Key Features Revealed
  6. Nothing Phone 3 to Get New Glyph Matrix Interface on the Rear Panel
  7. 16 Billion Login Credentials Have Been Leaked in Massive Data Breach
  8. YouTube Shorts Will Soon Let You Create AI Video Clips With Veo 3 Model
  9. Vivo T4 Lite 5G to Launch in India on June 24; Chipset Confirmed
  10. Samsung Galaxy Z Fold 7 Leaked Renders Suggest Design Changes
  1. 16 Billion Login Credentials Leaked in Massive Data Breach Impacting Apple, Google and More
  2. Vivo Y400 Pro 5G With 50-Megapixel Rear Camera, 5,500mAh Battery Launched in India: Price, Specifications
  3. Samsung Galaxy S25 FE Renders Leak Online, Suggesting Familiar Design With Thinner Bezels
  4. Samsung Galaxy Z Flip 7 Leaked Renders Suggest Edge-to-Edge Cover Display
  5. YouTube Shorts to Bring Google’s Veo 3 Video Generation Model With Audio Support 'This Summer'
  6. Samsung Galaxy Z Fold 7 Leaked Renders Hint at Design Changes; Storage Options Tipped
  7. Vivo Y400 Pro 5G Launching Today: Price in India, Expected Features and Specifications
  8. Fast Radio Bursts Reveal Universe’s Missing Matter Hidden in Cosmic Intergalactic Fog
  9. Apollo Astronauts Found Orange Glass Beads on the Moon, Scientists Now Know Why
  10. World’s Oldest Tailored Dress Found in Egyptian Tomb Dates Back Over 5,000 Years
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.