A critical vulnerability in LG's WebOS for smart TVs allows an attacker on the same local network to bypass authentication mechanisms and gain complete control of the device.

The flaw, which affects models such as the LG WebOS 43UT8050, allows unauthorized attackers to gain root access, install malicious apps, and completely compromise the TV. The vulnerability was revealed during the TyphoonPWN 2025 hacking competition.
The attack chain starts with a flaw in the browser- running on the TV. This service is activated on port 18888 when a USB storage device is plugged in. It exposes an API endpoint, /getFile, that can allow peer devices to download files from specific directories.
See also: WordPress: Critical vulnerability in Case Theme User plugin
According to SSD-Disclosure, the vulnerability is due to a lack of proper input validation in the path parameter, making the service vulnerable to path traversal. This allows an attacker to request and download any file from the TV's file system without requiring authorization.
By exploiting this path traversal flaw, an attacker can gain access to sensitive system files. The main target is the database file located in /var/db/main/, which contains authentication keys for clients that have previously connected to the TV's secondscreen.gateway service.
With these keys, the attacker can pretend to be a legitimate customer and log in to the secondscreen service, bypassing all authentication checks. This gives them high-privilege access to the TV's basic functions.

LG WebOS: A simple vulnerability allows full access to the TV
Once the attacker has access to the secondscreen service, they have the privileges they need to enable developer mode on the device. From there, they can use developer tools to install any application, including malware designed to spy on the user, steal data, or use the TV as a bot on a larger network of compromised devices.
See also: Vulnerabilities in Spring Security Framework bypass authorization
The proof-of-concept shows how an attacker can leverage this access to execute arbitrary commands, effectively gaining root control and taking over the TV. The entire process can be automated with a simple script, allowing for quick exploitation once initial access to the local network is gained.
In response to the disclosure, LG has issued security advisory SMR-SEP-2025 and urges LG WebOS users to ensure their devices are updated with the latest firmware.
TVs at risk
The LG WebOS vulnerability case highlights an often overlooked issue: smart TVs, while at the heart of everyday entertainment, are typically outside the strict security controls we apply to computers or mobile devices. This makes them attractive targets for cyberattacks, especially when they combine powerful computing power, stored data, and constant connection to the home network.

This vulnerability shows how easily a technical flaw, such as insufficient validation of a path parameter, can turn into a critical risk. An attacker who gains root access can not only install malicious applications, but also turn the TV into a “digital spy” in the living room. From activating microphones and cameras to exploiting the device as part of a botnet, the use cases are extremely worrying.
See also: Apple fixes vulnerability (backports) on old devices
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The incident also raises broader questions about the security of the Internet of Things (IoT). Consumers rarely update firmware or follow security advisories for TVs, and manufacturers don't always have a consistent policy of quickly releasing patches. This creates an environment where attackers can operate with relative ease.
LG proceeded with a notification and recommends immediate updating of devices, but the message is clear: the security of smart TVs must be treated with the same seriousness we devote to any other digital device.
