Lost in translation or hacked in translation? Subtitles with VLC, Kodi or another player? Better be careful where you download your subtitles: It turns out that attackers can infect subtitles with malicious code to exploit vulnerabilities in popular media players and take control of your device.
Researchers from security firm Check Point have discovered an unusual attack that relies on stealthily inserting malware into subtitle files. The list of vulnerable players so far includes popular applications such as: VLC, Kodi, Popcorn Time and Stremio.
According to their findings, security experts estimate that there are approximately 200 million streamers running vulnerable software, making this particular attack “one of the most widespread” at the moment.
Check Point has released a PoC that shows how remote code execution can be carried out in Popcorn Time and Kodi (you will find it at the end of the post).
What makes the attack particularly significant is that many of the media players involved and users consider subtitle repositories to be a “trusted source”.
Additionally, Check Point warns that antivirus software and other similar security alternatives often interpret subtitles as “benign text files” and scan them without attempting to carefully assess their nature.
“The attack relies heavily on the poor security of the way some media players handle subtitle files, as well as the large number of subtitle formats. To begin with, there are over 25 subtitle formats we use, each with unique features and capabilities,” their blog post states.
Since then, Check Point has notified major media player developers that are affected. Unfortunately, while some issues have already been fixed, there are others that still make the software vulnerable to this type of attack. For this reason, the security company has decided not to disclose further technical details in order to prevent further attacks.
Until then: Best to avoid popular subtitle repositories.
