Skip to main content

Subtitles hack can control your system through media player vulnerabilities

Hacked in Translation Demo
Researchers at Check Point Security Labs have uncovered a nasty new hacking technique that takes advantage security deficiencies in several popular media players. The exploit uses phony subtitle files to breach a user’s defenses, at which point it’s possible to gain complete control over the system.

Hackers can apparently create malicious subtitle files that run code when they’re loaded into a media player, according to the report published by Check Point. The company estimates that hundreds of millions of users running software like VLC, Kodi, Popcorn Time, and Stremio could be at risk.

Subtitle files are generally perceived as being harmless, and as such they’re rarely vetted too stringently by media players or antivirus software. The situation is made worse by the fact that there’s little standardization, with over 25 different formats with different features and capabilities currently in use.

Check Point has also determined that subtitle repositories are being manipulated to help distribute the malicious files to users. Subtitles submitted by attackers are having are being boosted in the rankings, making it more likely that they’ll be downloaded by users, and selected by media players that can download such files automatically.

Having discovered these vulnerabilities, Check Point disclosed the problem to the developers responsible for the media players that were tested. Some had already taken steps to address the issues, while others are still looking into the situation. As of the time of writing, VLC and Stremio have been officially updated with a fix, while a fixed version of Popcorn Time is available here, and a fixed source code release of Kodi is available here. There are still concerns that other media players might also be affected.

The key here is that subtitle files are being exploited because they’re widely considered to be innocuous. As soon as users and developers drop their guard, malicious hackers see their window of opportunity — and that’s why the work done by organizations like Check Point is so important.

Brad Jones
Former Digital Trends Contributor
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
The best all-in-one printers you can buy in 2024
Canon's imageClass MF753Cdw has a quick, full-duplex ADF.

If you're shopping for the best printers for a home office, an all-in-one is a good choice. Multifunction printers include scanners to digitize receipts, invoices, and other documents. The scan and print functions combine to make copies. Some all-in-one printers can connect to a phone line to act like a fax machine.

Multifunction printers are like the smaller cousins of the bulkier copiers you might see at the office. As our printer buyers' guide points out, an all-in-one printer usually costs less than it would to buy a printer and scanner separately. Here are some of the best multifunction printers on the market today.

Read more
Asus pits AMD’s performance against Intel’s efficiency
Asus ProArt PX13 front view showing display and keyboard.

Several new laptops chipsets have been introduced lately in response to Microsoft's Copilot+ PC AI initiative. They sport faster neural processing units (NPUs) to speed up on-device AI processing and make it more efficient, but they're not precisely the same. AMD's Ryzen AI 9 chipsets are aimed at overall performance, while Intel's Lunar Lake is aimed at efficiency.

The Asus ProArt PX13 is one of the first with AMD's chipset, and it's a highly portable 13-inch laptop. The Asus Zenbook S 14 is aimed at great battery life in a thin-and-light design using Lunar Lake. Both are some of the best laptops you can buy today, but which laptop is the better choice?
Specs and configurations

Read more
Nvidia might finally fix its VRAM problem — but it will take time
The Razer Blade 14 and 18 on a table.

It's no secret that some of Nvidia's best graphics cards could use a little more VRAM. According to a new leak, Nvidia may be addressing that problem in a big way -- at least in laptops. The RTX 5090 laptop GPU is now reported to come with 24GB VRAM across a 256-bit memory bus. The downside? These new laptops might not make it to market as soon as we'd hoped.

The information comes from Moore's Law Is Dead, who cites his own industry sources as he spills the beans on RTX 50-series laptop specs. Up until now, we've not heard much about Nvidia's plans for RTX 50 laptops, indicating that they might be a few months away. The YouTuber agrees with this, saying that Nvidia might be targeting a launch window in the first or second quarter of 2025. This might not affect the entire lineup, though.

Read more