Story image

Check Point uncovers major security flaw in LG smart devices

27 Oct 2017

With recent news from LG and Check Point, It’s like all your favourite horror movies have come true.

Check Point’s security researchers uncovered a vulnerability that exposed millions of users of LG SmartThinQ smart home devices to the risk of unauthorised remote control of their home appliances.

It’s undoubtedly concerning given the skyrocketing rise of smart applicances – in 2016 80 million smart home devices were shipped around the world, a 65 percent increase from the year before.

Deemed ‘HomeHack’, the vulnerabilities in the SmartThinQ mobile app and cloud application enabled the Check Point team to remotely login, take over the user’s legitimate account and gain control of the vacuum cleaner and its integral video camera.

Once in control of a specific user’s LG account, any LG device or appliance associated with that account could be controlled by the attacker – including the robot vacuum cleaner, refrigerators, ovens, dishwashers, washing machines and dryers, and air conditioners. 

Furthermore, the HomeHack vulnerability equipped attackers with the ability to spy on users’ home activities via the Hom-Bot robot vacuum cleaner video camera that sends live video to the associated LG SmartThinQ app as part of its HomeGuard Security feature.

“As more and more smart devices are being used in the home, hackers will shift their focus from targeting individual devices, to hacking the apps that control networks of devices. This provides cyber criminals with even more opportunities to exploit software flaws, cause disruption in users’ homes and access their sensitive data,” says Oded Vanunu, head of products vulnerability research at Check Point.

“Users need to be aware of the security and privacy risks when using their IoT devices and it’s essential that IoT manufactures focus on protecting smart devices against attacks by implementing robust security during the design of software and devices.”

Check Point disclosed the vulnerability to LG on July 31 2017, following responsible disclosure guidelines and LG responded by fixing the reported issues in the SmartThinQ application at the end of September.

Vanunu says fortunately LG responsibly provided a quality fix to stop possible exploitation of the issues.

“In August, LG Electronics teamed with Check Point Software Technologies to run an advanced rooting process designed to detect security issues and immediately began updating patch programs,” says Koonseok Lee, manager of the smart development team within smart solution BD at LG Electronics.

“Effective September 29th the security system has been running the updated 1.9.20 version smoothly and issue-free.  LG Electronics plans to continue strengthening its software security systems as well as work with cyber-security solution providers like Check Point to provide safer and more convenient appliances.” 

In terms of protecting devices, Check Point and LG recommend:

  • Update LG SmartThinQ app to the latest version (V1.9.23)
  • Update smart home physical devices with the latest version
Avi Networks: Using visibility to build trust
Visibility, also referred to as observability, is a core tenet of modern application architectures for basic operation, not just for security.
Privacy: The real cost of “free” mobile apps
Sales of location targeted advertising, based on location data provided by apps, is set to reach $30 billion by 2020.
Myth-busting assumptions about identity governance - SailPoint
The identity governance space has evolved and matured over the past 10 years, changing with the world around it.
Forrester names Crowdstrike leader in incident response
The report provides an in-depth evaluation of the top 15 IR service providers across 11 criteria.
Slack doubles down on enterprise key management
EKM adds an extra layer of protection so customers can share conversations, files, and data while still meeting their own risk mitigation requirements.
Security professionals want to return fire – Venafi
Seventy-two percent of professionals surveyed believe nation-states have the right to ‘hack back’ cybercriminals.
Alcatraz AI to replace corporate badges with AI security
The Palo Alto-based startup supposedly leverages facial recognition, 3D sensing, and machine learning to enable secure access control.
Unencrypted Gearbest database leaves over 1.5mil shoppers’ records exposed
Depending on the countries and information requirements, the data could give hackers access to online government portals, banking apps, and health insurance records.