Attackers can use video subtitles to hijack your devices

in hijack •  7 years ago 

Be careful before you fire up media player software to play that foreign-language movie -- it might be a way for intruders to compromise your system. Check Point researchers have discovered an exploit that uses maliciously crafted subtitles to take control of your device, whether it's a PC, phone or smart TV. It's not picky about the program, either -- the researchers demonstrated the flaw in Kodi, PopcornTime, Stremio and VLC. The technique isn't particularly complicated, and relies on a tendency by developers to assume that subtitles are little more than innocuous text files.

Read more here: https://www.engadget.com/2017/05/24/security-flaw-in-media-player-subtitles/

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

Attackers can use pretty much anything at this point.

Good to know. It's weird that so many different programs are vulnerable to the same data-driven attack. I bet they all use some of the same libraries.