Chromecast PewDiePie hack exposes long-standing unpatched bug

Exploiting a Chromecast bug that's been allegedly ignored by Google for almost five years, in combination with an inherent security flaw in some routers, a hacker has taken control of thousands of users’ Chromecast-connected devices.

Hacker Giraffe has remotely gained access to the TVs and smart devices of tens-of-thousands of users and displayed a pop-up that both warns of the exploit and links to a page listing the current number of affected devices. 

Teaching an old bug new tricks

While technically this latest hack is made possible via a security flaw in a users’ router, the exploit related to the Chromecast is one that has been known since the year the device launched.

In 2014, security firm Bishop Fox found that it could gain control of a Chromecast by disconnecting it from its current Wi-Fi network in what’s known as a “deauth” attack and reverting it to a factory state. 

It was confirmed that the device was still vulnerable to these attacks in 2016 by Pen Test Partners, another cybersecurity firm.

While the initial deauth attacks required the hacker to be within range of the target’s Wi-Fi network, this new breed of attack can occur remotely over the internet, via the UPnP flaw previously mentioned. 

TOPICS
Harry Domanski
Harry is an Australian Journalist for TechRadar with an ear to the ground for future tech, and the other in front of a vintage amplifier. He likes stories told in charming ways, and content consumed through massive screens. He also likes to get his hands dirty with the ethics of the tech.