uTorrent vulnerabilities leave users at risk of hacking and snooping

uTorrent on a laptop

uTorrent's Windows desktop and web clients both contain vulnerabilities that leave users at risk of hacking.

The problem was discovered by Tavis Ormandy of Google Project Zero – a team of security analysts who specialize in finding zero-day vulnerabilities (ones that the developers or publishers are unaware of).

According to Ormandy the flaws are easy to exploit, and make it possible for criminals to control key functions in the client, including seeing your downloaded files and downloading malware that will run the next time you boot your PC.

Project Zero gives software vendors 90 days to fix vulnerabilities before making them public. Ormandy originally contacted BitTorrent about the flaw in November, but received no response. Fearing BitTorrent wouldn't make the deadline, he reached out to founder Bram Cohen on Twitter, prompting the company to act.

How to patch uTorrent

BitTorrent has issued a fix in its latest beta release, and plans to push a new stable version of the client out to all users later this week.

The web version of uTorrent has already been repaired, according to Dave Rees, vice president of engineering at BitTorrent. 

"We highly encourage all uTorrent Web customers to update to the latest available build 0.12.0.502 available on our website and also via the in-application update notification," he said in an email to users.

Via Ars Technica

Cat Ellis
Homes Editor

Cat is TechRadar's Homes Editor specializing in kitchen appliances and smart home technology. She's been a tech journalist for 15 years and is an SCA-certified barista, so whether you want to invest in some smart lights or pick up a new espresso machine, she's the right person to help.

Latest in Computing Security
Dark Web monitoring
How users benefit from Dark Web monitoring
The X logo next to a silhouette of Elon Musk
Who was really behind the massive X cyberattack? Here’s what experts say about Elon Musk’s claims
A person holding a phone looking at a scam text with warning signs around
A massive SMS toll fee scam is sweeping the US – here’s how to stay safe, according to the FBI
View on National Assembly building in Paris, France, with French and European flags flying.
France rejects controversial encryption backdoor provision
ensure data security for your business
The complete data protection system for your business
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring