Skip to main content

Subtitles hack can control your system through media player vulnerabilities

Hacked in Translation Demo
Researchers at Check Point Security Labs have uncovered a nasty new hacking technique that takes advantage security deficiencies in several popular media players. The exploit uses phony subtitle files to breach a user’s defenses, at which point it’s possible to gain complete control over the system.

Hackers can apparently create malicious subtitle files that run code when they’re loaded into a media player, according to the report published by Check Point. The company estimates that hundreds of millions of users running software like VLC, Kodi, Popcorn Time, and Stremio could be at risk.

Recommended Videos

Subtitle files are generally perceived as being harmless, and as such they’re rarely vetted too stringently by media players or antivirus software. The situation is made worse by the fact that there’s little standardization, with over 25 different formats with different features and capabilities currently in use.

Check Point has also determined that subtitle repositories are being manipulated to help distribute the malicious files to users. Subtitles submitted by attackers are having are being boosted in the rankings, making it more likely that they’ll be downloaded by users, and selected by media players that can download such files automatically.

Having discovered these vulnerabilities, Check Point disclosed the problem to the developers responsible for the media players that were tested. Some had already taken steps to address the issues, while others are still looking into the situation. As of the time of writing, VLC and Stremio have been officially updated with a fix, while a fixed version of Popcorn Time is available here, and a fixed source code release of Kodi is available here. There are still concerns that other media players might also be affected.

The key here is that subtitle files are being exploited because they’re widely considered to be innocuous. As soon as users and developers drop their guard, malicious hackers see their window of opportunity — and that’s why the work done by organizations like Check Point is so important.

Brad Jones
Former Digital Trends Contributor
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
Microsoft calls Recall one of ‘the most secure experiences’ it’s ever built
Recall promotional image.

As part of its Ignite 2024 announcements, Microsoft has provided an update on how its AI-powered Recall feature will work in the context of an IT department. Noting that the company has "heard your feedback," specifically in terms of it needing it to be more "secure and controllable," Microsoft claims to have gotten its ducks in a row for the launch of its controversial new Windows 11 feature.

Microsoft says that Recall "will ship with meaningful security enhancements, including additional layers of data encryption and Windows Hello protection, making it one of the most secure experiences we have ever built." Whether or not this will be enough to satisfy the security community, however, is still to be determined.

Read more
Windows 11 is finally coming to the Quest 3 and Quest 3S
A visualization of Windows being used on a headset.

Microsoft has announced that Windows 11 support is officially coming to the Quest 3 and Quest 3S headsets. The announcement comes as part of Microsoft Ignite 2024, which was otherwise focused on updates to its Copilot AI systems. And though not many details were shared on the mixed reality front, it's nice to see the support finally arrive.

According to the announcement, the update will bring "the full capabilities of Windows 11 to mixed reality headsets" through either a local Windows PC or a Windows 365 Cloud PC. The point, of course, is not to bring PC games into VR, but rather to do to work in mixed reality. You'll be able to have multiple virtual monitors all at your disposal to use however you want, regardless of the physical space you're working in.

Read more
With Copilot Actions, Microsoft brings AI agents to Outlook, Teams, and more
microsoft expanding ai agents 365 copilot early 2025 actions2

Microsoft plans to roll out a slew of new features for its business-facing 365 Copilot products starting early next year, the company announced during its Microsoft Ignite 2024 event on Tuesday.

365 Copilot, which was rebranded from just Copilot in September, enables businesses to incorporate Microsoft Copilot generative AI into its Microsoft 365 family of apps (as well as in Teams) for a $30/employee/month subscription.

Read more