logo

For Smart TVs, Malware May Hide In Broadcast Content

ID: 92d83b0c-005b-51ef-bf91-a2508f4c7a53

STIX ID: report--92d83b0c-005b-51ef-bf91-a2508f4c7a53

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2014-06-12

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

Researchers at Columbia University describe a weakness in the HbbTV standard used by many smart TVs and broadcast-broadband devices that allows broadcasters to assign origins to embedded web content, effectively violating the web Same-Origin Policy. This design flaw enables malicious broadcast-delivered applications or RF-injected payloads to run arbitrary JavaScript on affected devices (demonstrated via proof-of-concept autostart apps), potentially forcing devices to visit attacker-controlled web pages, harvest credentials, manipulate online ratings, or carry out large-scale localized attacks; the authors note low complexity and minimal cost (≈$450) for attackers to target thousands of devices in a dense area, though no active exploitation in the wild is reported in the article.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.