LG TVs Expose Remote-Code-Execution Flaws, Allowing Audio Capture When Off
Updated
Updated · Malwarebytes Labs · Sep 7
LG TVs Expose Remote-Code-Execution Flaws, Allowing Audio Capture When Off
3 articles · Updated · Malwarebytes Labs · Sep 7
Summary
Researchers said several LG smart TV models contain remote-code-execution vulnerabilities that could let a compromised set record microphone audio, including when the TV appears off.
Gamers Nexus, Level1Techs and independent researchers also found the TVs mapping local networks—identifying phones, PCs, printers and smart-home devices—and collecting nearby Wi-Fi names, signal data and device identifiers.
Combined with ACR viewing data and advertising IDs, that information could build detailed household profiles and give attackers a foothold to probe other devices on home or business networks.
Full exploit details were withheld during responsible disclosure to LG; users were urged to install firmware updates, disable ACR, voice and ad features, and isolate TVs on a separate IoT or guest network.