Hacked by subtitles

Scary_Turtle

Expert Member
Joined
Aug 13, 2015
Messages
3,205
Just found this http://hackaday.com/2017/05/25/hacked-by-subtitles/ seems pretty reliable after googling this there are many sites that verify it.

Basically VLC, Kodi (XBMC), Popcorn-Time and strem.io have an exploit where if the user downloads subtitles their PC could be taken over.

Kodi 17.3 has fixed this issue so make sure you update.
 

Ninji

Banned
Joined
Mar 20, 2017
Messages
235
Yet another example of badly written code... assuming garbage collection is/was always there.
 

Batista

Executive Member
Joined
Sep 2, 2011
Messages
7,909
I open each srt file with notepad, dont use automated subtitles with anything.
 

durbandave

Senior Member
Joined
Sep 8, 2006
Messages
856
My understanding on the VLC side is that the exploit is not available in the latest version
 
Top