sb-eu logo
Story image

Check Point uncovers major security flaw in LG smart devices

27 Oct 2017

With recent news from LG and Check Point, It’s like all your favourite horror movies have come true.

Check Point’s security researchers uncovered a vulnerability that exposed millions of users of LG SmartThinQ smart home devices to the risk of unauthorised remote control of their home appliances.

It’s undoubtedly concerning given the skyrocketing rise of smart applicances – in 2016 80 million smart home devices were shipped around the world, a 65 percent increase from the year before.

Deemed ‘HomeHack’, the vulnerabilities in the SmartThinQ mobile app and cloud application enabled the Check Point team to remotely login, take over the user’s legitimate account and gain control of the vacuum cleaner and its integral video camera.

Once in control of a specific user’s LG account, any LG device or appliance associated with that account could be controlled by the attacker – including the robot vacuum cleaner, refrigerators, ovens, dishwashers, washing machines and dryers, and air conditioners. 

Furthermore, the HomeHack vulnerability equipped attackers with the ability to spy on users’ home activities via the Hom-Bot robot vacuum cleaner video camera that sends live video to the associated LG SmartThinQ app as part of its HomeGuard Security feature.

“As more and more smart devices are being used in the home, hackers will shift their focus from targeting individual devices, to hacking the apps that control networks of devices. This provides cyber criminals with even more opportunities to exploit software flaws, cause disruption in users’ homes and access their sensitive data,” says Oded Vanunu, head of products vulnerability research at Check Point.

“Users need to be aware of the security and privacy risks when using their IoT devices and it’s essential that IoT manufactures focus on protecting smart devices against attacks by implementing robust security during the design of software and devices.”

Check Point disclosed the vulnerability to LG on July 31 2017, following responsible disclosure guidelines and LG responded by fixing the reported issues in the SmartThinQ application at the end of September.

Vanunu says fortunately LG responsibly provided a quality fix to stop possible exploitation of the issues.

“In August, LG Electronics teamed with Check Point Software Technologies to run an advanced rooting process designed to detect security issues and immediately began updating patch programs,” says Koonseok Lee, manager of the smart development team within smart solution BD at LG Electronics.

“Effective September 29th the security system has been running the updated 1.9.20 version smoothly and issue-free.  LG Electronics plans to continue strengthening its software security systems as well as work with cyber-security solution providers like Check Point to provide safer and more convenient appliances.” 

In terms of protecting devices, Check Point and LG recommend:

  • Update LG SmartThinQ app to the latest version (V1.9.23)
  • Update smart home physical devices with the latest version
Story image
CrowdStrike integrates with ServiceNow program to bolster incident response
As part of the move, users can now integrate device data from the CrowdStrike Falcon platform into their incident response process, allowing for the improvement of both the security and IT operation outcomes.More
Story image
The guide to digital security in unstable times
An increase in vulnerability across different sectors has meant that 2020 has seen more than its fair share of cybersecurity incidents. One of the most effective ways to combat the perils of today’s cyber-threats is to gain a better knowledge of the threat vectors looming over the heads of organisations. More
Story image
Shlayer malware proves Apple devices aren't as secure as you think
"Apple never talks about malware publicly, and loves to give the impression that its systems are secure. Unfortunately, the opposite has been proven to be the case with great regularity."More
Story image
Zero trust is the way to secure the distributed workforce - Empired
Existing security solutions need to evolve to accommodate the new remote workforce.More
Story image
OT networks warned of vulnerabilities in CodeMeter software
Manufacturers using the Wibu-Systems CodeMeter third-party licence management solution are being urged to remain vigilant and to urgently update the solution to CodeMeter version 7.10.More
Story image
Misinformation on the rise, organisations consider how best to respond
The increase in misinformation and fake domains have left organisations perceiving the threat level to be ‘very significant’, with a third planning greater emphasis on their ability to respond in coming months.More