logo

LG WebOS TV Vulnerability Let Attackers Bypass Authentication and Enable Full Device Takeover

ID: 02cd5fee-4a64-5117-b114-b217377101a7

STIX ID: report--02cd5fee-4a64-5117-b114-b217377101a7

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-09-16

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A critical path-traversal vulnerability in LG WebOS's browser-service (port 18888) lets unauthenticated local attackers retrieve sensitive files (notably /var/db/main/ pairing keys), impersonate secondscreen clients, enable developer mode, and gain root control to install malware or otherwise fully compromise affected TVs; a PoC was shown at TyphoonPWN 2025 and LG released advisory SMR-SEP-2025 recommending firmware updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.