LG WebOS TV Vulnerability Let Attackers Bypass Authentication and Enable Full Device Takeover
ID: 02cd5fee-4a64-5117-b114-b217377101a7
STIX ID: report--02cd5fee-4a64-5117-b114-b217377101a7
Feed Name: cybersecurityNews.com
Threat Score
A critical path-traversal vulnerability in LG WebOS's browser-service (port 18888) lets unauthenticated local attackers retrieve sensitive files (notably /var/db/main/ pairing keys), impersonate secondscreen clients, enable developer mode, and gain root control to install malware or otherwise fully compromise affected TVs; a PoC was shown at TyphoonPWN 2025 and LG released advisory SMR-SEP-2025 recommending firmware updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
