lg

thousands-of-lg-tvs-are-vulnerable-to-takeover—here’s-how-to-ensure-yours-isn’t-one

Thousands of LG TVs are vulnerable to takeover—here’s how to ensure yours isn’t one

Thousands of LG TVs are vulnerable to takeover—here’s how to ensure yours isn’t one

Getty Images

As many as 91,000 LG TVs face the risk of being commandeered unless they receive a just-released security update patching four critical vulnerabilities discovered late last year.

The vulnerabilities are found in four LG TV models that collectively comprise slightly more than 88,000 units around the world, according to results returned by the Shodan search engine for Internet-connected devices. The vast majority of those units are located in South Korea, followed by Hong Kong, the US, Sweden, and Finland. The models are:

  • LG43UM7000PLA running webOS 4.9.7 – 5.30.40
  • OLED55CXPUA running webOS 5.5.0 – 04.50.51
  • OLED48C1PUB running webOS 6.3.3-442 (kisscurl-kinglake) – 03.36.50
  • OLED55A23LA running webOS 7.3.1-43 (mullet-mebin) – 03.33.85

Starting Wednesday, updates are available through these devices’ settings menu.

Got root?

According to Bitdefender—the security firm that discovered the vulnerabilities—malicious hackers can exploit them to gain root access to the devices and inject commands that run at the OS level. The vulnerabilities, which affect internal services that allow users to control their sets using their phones, make it possible for attackers to bypass authentication measures designed to ensure only authorized devices can make use of the capabilities.

“These vulnerabilities let us gain root access on the TV after bypassing the authorization mechanism,” Bitdefender researchers wrote Tuesday. “Although the vulnerable service is intended for LAN access only, Shodan, the search engine for Internet-connected devices, identified over 91,000 devices that expose this service to the Internet.”

The key vulnerability making these threats possible resides in a service that allows TVs to be controlled using LG’s ThinkQ smartphone app when it’s connected to the same local network. The service is designed to require the user to enter a PIN code to prove authorization, but an error allows someone to skip this verification step and become a privileged user. This vulnerability is tracked as CVE-2023-6317.

Once attackers have gained this level of control, they can go on to exploit three other vulnerabilities, specifically:

  • CVE-2023-6318, which allows the attackers to elevate their access to root
  • CVE-2023-6319, which allows for the injection of OS commands by manipulating a library for showing music lyrics
  • CVE-2023-6320, which lets an attacker inject authenticated commands by manipulating the com.webos.service.connectionmanager/tv/setVlanStaticAddress application interface.

Thousands of LG TVs are vulnerable to takeover—here’s how to ensure yours isn’t one Read More »

the-5-most-interesting-pc-monitors-from-ces-2024

The 5 most interesting PC monitors from CES 2024

Dell UltraSharp 40 Curved Thunderbolt Hub Monitor (U4025QW)

Enlarge / Dell’s upcoming UltraSharp U4025QW.

Scharon Harding

Each year, the Consumer Electronics show brings a ton of new computer monitor announcements, and it’s often difficult to figure out what’s worth paying attention to. When it comes to the most interesting models this year, there were two noteworthy themes.

First of all, my complaint in 2022 about there not being enough OLED monitors was largely addressed this year. CES revealed many plans for OLED monitors in 2024, with a good number of those screens set to be appropriately sized for desktops. That includes the introduction of 32-inch, non-curved QD-OLED options and other smaller screens for people who have been waiting for OLED monitors in more varied form factors.

Secondly, with more people blending their work and home lives these days, CES brought hints that the line between gaming monitors and premium monitors used for general or even professional purposes will be blurring more in the future. We’re not at the point where the best productivity monitor and ideal gaming monitor perfectly align in a single product. But this week’s announcements have me imagining ways that future monitors could better serve users with serious work and play interests.

For now, here are the most intriguing monitors from CES 2024.

Dell UltraSharps hit 120 Hz

  • Dell started adding 120 Hz models to its UltraSharp series.

    Scharon Harding

  • This monitor is VESA DisplayHDR 600-certified.

    Dell

  • Ports include Thunderbolt 4 with 140 W power delivery. There’s also a pop-out box of ports by the monitor’s chin.

    Dell

Dell UltraSharp monitors have long attracted workers and creatives and, with their USB-C connectivity, even Mac users. The last few CES shows have shown Dell attempting to improve its lineup, with the most landmark innovation being the introduction of IPS Black. With CES 2024, though, Dell focused on improved video resolution.

Dell’s UltraSharp 40 Curved Thunderbolt Hub Monitor (U4025QW), pictured above, is a 39.7-inch ultrawide with a 5120×2160 resolution and a 120 Hz refresh rate. As most monitors are aimed at workers still using 60 Hz, this is a big step up for people with systems capable of supporting 11,059,200 pixels at 120 frames per second. Such speeds have been relegated to gaming monitors for a while, but with TVs moving to higher refresh rates (with encouragement from gaming consoles), more people are becoming accustomed to faster screens. And with other attributes, like a 2500R curve, we wouldn’t blame workers for doing some light gaming on the U4025QW, too.

But Dell says the refresh rate boost is about increasing eye comfort. The UltraSharp U4025QW is one of two monitors with 5-star certification from TÜV Rheinland’s new Eye Comfort program, which Dell helped create, a Dell spokesperson told me last month at a press event.

According to TÜV, the certification program “is no longer limited to the old low-blue-light or flicker-free labels” and now “covers a broader range of safety indicators, such as ambient brightness, color temperature adjustment and regulation, and brightness.” New requirements include brightness and color temperature control for different ambient lighting. Dell’s ultrawide covers this with an integrated ambient light sensor.

The certification also requires a minimum 120 Hz refresh rate, which is probably where Dell got the number from. A Dell spokesperson confirmed to Ars that the use of IPS Black didn’t impact the monitor’s ability to get TÜV certifications and that it could have theoretically earned five stars with another panel type, like VA.

Dell announced bringing 120 Hz to the UltraSharp lineup in November when it debuted two 24-inch and two 27-inch UltraSharp monitors with 120 Hz refresh rates. At CES, Dell proved this upgrade wasn’t a fluke relegated to its smaller UltraSharps and went all in, bringing the refresh rate to a top-line ultrawide 5K Thunderbolt 4 monitor.

The U4025QW has an updated version of ComfortView Plus, which uses hardware to lower blue light levels. I’ve seen it function without making colors turn yellowish, as some other blue-light-fighting techniques do. After not significantly updating ComfortView Plus since its 2020 release, Dell now says it’s using a “more advanced LED backlight” to reduce blue light exposure from 50 percent to under 35 percent.

The effects are minimal, though. Dell-provided numbers claim the reduced blue light exposure could reduce eye fatigue by 8 percent after 50 minutes, but we should take that with a grain of salt. It’s nearly impossible to quantify how well blue light reduction techniques work from person to person.

The UltraSharp U4025QW releases on February 27, starting at $2,400.

The 5 most interesting PC monitors from CES 2024 Read More »

meta-is-reportedly-partnering-with-lg-to-create-apple-vision-pro-competitor

Meta is Reportedly Partnering with LG to Create Apple Vision Pro Competitor

Meta is reportedly teaming up with South Korean tech giant LG Electronics to offer up competition to the Apple’s forthcoming Vision Pro mixed reality headset, which is slated to arrive sometime in 2024.

South Korea’s Maekyung (Korean) is reporting on two new Meta headsets: a low-cost Quest model that will be priced at “less than $200” coming in 2024, and a high-priced model in a joint venture with LG in 2025, which is supposedly set to take on Apple Vision Pro.

The report maintains the name of the Meta/LG headset will be ‘Meta Quest 4 Pro’.

Mass production of the so-called Quest 4 Pro is allegedly being handled by LG Electronics, and LG Display, with LG Innotek and LG Energy Solution supplying parts.

Provided the report is true, it seems some very distinct battle lines are being drawn. Samsung announced earlier this year that it was working with Qualcomm and Google to develop an Android-powered XR device, which may also be positioned to compete against Apple and Meta.

Meta is Reportedly Partnering with LG to Create Apple Vision Pro Competitor Read More »