HomeSecurityLG app allows full device control

LG app allows full control of the device

LG

The protocol used in the On-screen Phone app on LGhas been found to be vulnerable to authentication bypass, allowing complete control of the mobile device.

The On-screen Phone app, from the well-known electronics and electrical appliance company, offers remote control of the computer via mobile devices. Among the app's features, there is the ability to use the phone directly from the computer, to exchange messages, as well as to transfer data between the two terminals.

The phone screen is also displayed on the computer, so that any notification that comes in becomes available on both devices, which can be connected via USB or a wireless network.

When receiving the login message from a computer, an LG phone equipped with the app asks the owner for approval. Imre Rad, a security researcher in Hungary at SEARCH-LAB, found that the confirmation request from the phone owner can be bypassed by an attacker who is on the same network as the victim.

Once the connection between the two devices is active, the controller from the computer gains access to all the locations of the phone and is able to install malware for monitoring or to extract confidential financial data.

This vulnerability has the identifier CVE-2014-8757 and affects all versions of the application from 4.3.009 onwards.

The company has already taken action to fix the problem and has released the new version 4.3.010. Owners of these mobile phones should check for the new version in the LG update center and install it.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS