Video Subtitle Files for Media Players Can Be Used to Take Control of Any Device: Report

Advertisement
By Ketan Pratap | Updated: 25 May 2017 11:57 IST
Highlights
  • Check Point researchers discovered the malicious subtitles
  • Researchers found popular media players like VLC and other infected
  • Fixed version for VLC, Kodi, Popcorn-Time and strem.io available

Researchers have claimed that popular media players are vulnerable to malicious subtitles files that could allow attackers to take control of any type of device. The researchers estimate that roughly 200 million video players and online streamers are currently vulnerable to such an attack.

The researchers at Check Point say that the malicious subtitle files once downloaded for a media player use could help attackers "complete control over any type of device" via vulnerabilities found in many popular streaming platforms including VLC, Kodi, Popcorn-Time and strem.io.

Check Point researchers further explain, "Our research reveals a new possible attack vector, using a completely overlooked technique in which the cyberattack is delivered when movie subtitles are loaded by the user's media player. These subtitles repositories are, in practice, treated as a trusted source by the user or media player; our research also reveals that those repositories can be manipulated and be made to award the attacker's malicious subtitles a high score, which results in those specific subtitles being served to the user. This method requires little or no deliberate action on the part of the user, making it all the more dangerous."

Advertisement

Unlike traditional attacks, movie subtitles is usually seen as a benign text file by the system which means antivirus software, and other security solutions vet them without trying to assess their real nature, leaving millions of users exposed to this risk.

Advertisement

Once the attacker takes control of the victim's device whether it is a computer, a smart TV, or a mobile device, the potential damage the attacker can inflict is endless, ranging anywhere from stealing sensitive information, installing ransomware, mass Denial of Service attacks, and much more.

Check Point researchers tested and found vulnerabilities in four popular media players like VLC, Kodi, Popcorn Time and Stremio. The media players have received patches to avoid the attack by malicious subtitles, and users can download the fixes via the Check Point site.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon to Cut Thousands More Jobs Globally With India Being the Worst-Hit
  2. Vivo X200T Launched in India With These Features
  3. Nothing Phone 4a Lands on TDRA Certification Database Ahead of Its Debut
  4. Amazfit Active Max With 1.5-Inch AMOLED Display Launched in India: See Price
  5. HP HyperX Omen 15 Gaming Laptop With RTX 5060 GPU Launched in India
  6. Motorola Edge 70 Fusion Leaked Renders Hint at a Slightly Updated Design
  7. Samsung Galaxy A07 5G Price in India Leaks Ahead of Launch
  8. Samsung Galaxy A57 Surfaces on Chinese Certification Site With This Design
  9. Here's When the iQOO 15R Will Launch in India
  10. Oppo K15 Launch Seems Imminent as Company Teases Launch of a New Phone
  1. Sony Said to Be Planning State of Play Broadcast for February
  2. Amazon to Reportedly Layoff 16,000 Employees, India Might Be Among Worst-Hit Regions
  3. Hashtag Star Now Available for Streaming on Chaupal: What You Need to Know About This Punjabi Film
  4. The Conjuring: Last Rites OTT Release Date Revealed: Know When and Where to Watch it Online?
  5. Dust Bunny Now Available for Rent on Prime Video, YouTube, and More
  6. Samsung Will Reportedly Produce 1 Million Galaxy Wide Fold Units to Compete With Apple's Foldable iPhone
  7. Oppo K15 Series Launch Seems Imminent as Company Teases Arrival of New K Series Smartphone
  8. OpenAI Claims Scientists Are Increasingly Using ChatGPT as a Research Collaborator
  9. Motorola Edge 70 Fusion Design Renders Leaked Online; Minor Updates to Familiar Design Anticipated
  10. Arc Raiders' New 'Headwinds' Update Releases January 27, Four-Month Content Roadmap Revealed
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.