Sony Bravia smart TVs had photo app vulnerability

Spread the love

Sony and security company Fortinet advise owners of Bravia TVs with the Photo Sharing Plus to update the firmware. The photo application on the TVs contains a vulnerability that can be exploited remotely.

Sony recently announced that due to a security issue with the Photo Sharing Plus app, new firmware has been released for the Bravia models R5C, WD75, WD65, XE70, XF70, WE75, WE6 and WF6. The app allows users to display photos and video from smartphone or tablet.

The application was found to be susceptible to stack buffer overflows, directory traversal and command injection, allowing attackers to run code without authentication on the TVs, with elevated privileges. However, the attacker must already have access to the same network that the TV is connected to, which limits the impact.

Fortinet is publishing details of the vulnerability now that Sony has finalized the distribution of the ota update. The security company discovered the issue on March 27, and on April 3, Sony began developing a patch, which was offered from June 1.

You might also like