Sunday, June 11, 2017

Smart TV hack embeds attack code into broadcast signal—no access required


The proof-of-concept exploit uses a low-cost transmitter to embed malicious commands into a rogue TV signal. That signal is then broadcast to nearby devices. It worked against two fully updated TV models made by Samsung. By exploiting two known security flaws in the Web browsers running in the background, the attack was able to gain highly privileged root access to the TVs. By revising the attack to target similar browser bugs found in other sets, the technique would likely work on a much wider range of TVs. - Dan Goodin, Ars Technica UK [via/web:http://streaming-tv.us]

1 comment: