Story image

Check Point uncovers major security flaw in LG smart devices

27 Oct 2017

With recent news from LG and Check Point, It’s like all your favourite horror movies have come true.

Check Point’s security researchers uncovered a vulnerability that exposed millions of users of LG SmartThinQ smart home devices to the risk of unauthorised remote control of their home appliances.

It’s undoubtedly concerning given the skyrocketing rise of smart applicances – in 2016 80 million smart home devices were shipped around the world, a 65 percent increase from the year before.

Deemed ‘HomeHack’, the vulnerabilities in the SmartThinQ mobile app and cloud application enabled the Check Point team to remotely login, take over the user’s legitimate account and gain control of the vacuum cleaner and its integral video camera.

Once in control of a specific user’s LG account, any LG device or appliance associated with that account could be controlled by the attacker – including the robot vacuum cleaner, refrigerators, ovens, dishwashers, washing machines and dryers, and air conditioners. 

Furthermore, the HomeHack vulnerability equipped attackers with the ability to spy on users’ home activities via the Hom-Bot robot vacuum cleaner video camera that sends live video to the associated LG SmartThinQ app as part of its HomeGuard Security feature.

“As more and more smart devices are being used in the home, hackers will shift their focus from targeting individual devices, to hacking the apps that control networks of devices. This provides cyber criminals with even more opportunities to exploit software flaws, cause disruption in users’ homes and access their sensitive data,” says Oded Vanunu, head of products vulnerability research at Check Point.

“Users need to be aware of the security and privacy risks when using their IoT devices and it’s essential that IoT manufactures focus on protecting smart devices against attacks by implementing robust security during the design of software and devices.”

Check Point disclosed the vulnerability to LG on July 31 2017, following responsible disclosure guidelines and LG responded by fixing the reported issues in the SmartThinQ application at the end of September.

Vanunu says fortunately LG responsibly provided a quality fix to stop possible exploitation of the issues.

“In August, LG Electronics teamed with Check Point Software Technologies to run an advanced rooting process designed to detect security issues and immediately began updating patch programs,” says Koonseok Lee, manager of the smart development team within smart solution BD at LG Electronics.

“Effective September 29th the security system has been running the updated 1.9.20 version smoothly and issue-free.  LG Electronics plans to continue strengthening its software security systems as well as work with cyber-security solution providers like Check Point to provide safer and more convenient appliances.” 

In terms of protecting devices, Check Point and LG recommend:

  • Update LG SmartThinQ app to the latest version (V1.9.23)
  • Update smart home physical devices with the latest version
50 million tonnes of e-waste: IT faces sustainability challenges
“Through This is IT, we want to help people better understand the problem of today’s linear “take, make, dispose” thinking around IT products and its effects like e-waste, pollution and climate change."
Vocus & Vodafone unbundle NZ's fibre network
“Unbundling fibre will provide retail service providers with a flexible future-proofed platform regardless of what tomorrow brings."
NZ Cricket ups data analytics game with Qrious
The Black Caps and White Ferns have implemented a data and analytics solution from Qrious to monitor and improve game strategy and player performance.
Gartner: Smartphone biometrics coming to the workplace
Gartner predicts increased adoption of mobile-centric biometric authentication and SaaS-delivered IAM.
Samsung & Trade Me offer AI-powered shopping
The smartphone camera & AI-powered tech, Trade Me says, is a ‘glimpse into the future of shopping’.
Neill Blomkamp's 'Conviction' is a prequel to BioWare's Anthem
You may remember Neill Blomkamp’s name from such films as District 9, Chappie, and Elysium. If you’ve seen any of those films, the short teaser trailer will seem somewhat familiar to you.
Security flaw in Xiaomi electric scooters could have deadly consequences
An attacker could target a rider, and then cause the scooter to suddenly brake or accelerate.
617 million stolen records up for sale on dark web
It may not be the first time the databases have been offered for sale.