Skip to main content
  1. Home
  2. Computing
  3. Audio / Video
  4. News

Who’s watching what you’re watching? Avast finds vulnerabilities in Vizio smart TVs

Add as a preferred source on Google

Security researchers at Avast have demonstrated a number of vulnerabilities and potential attacks against Vizio smart TVs, including intercepting data that displays a person’s viewing habits.

Under the wide umbrella of the Internet of things and smart homes, Avast began to pull apart the security of a Vizio smart TV and found that it was susceptible to man-in-the-middle attacks due to HTTPS certificates that were not being validated.

Recommended Videos

Avast discovered that the TV was constantly accessing tvinteractive.tv, a website run by a company called Cognitive Networks. The service appears to gather a timestamp that reports what someone is watching and when, and then sends that info to the content provider or advertisers. Avast even discovered that the TV would accept a forged certificate when connecting to the site as it does not fully validate the HTTPS certificate. Instead it just validates the checksum at the end of the data being transferred.

Essentially, the HTTPS certificate is what makes a connection secure, validating the information and telling the sender what a site actually is. Without it, a hacker could potentially steal the information. Carrying out a man-in-the-middle attack in which it impersonated the tvinteractive.tv with forged HTTPS credentials, Avast was able to crack the data that was being sent and view it.


“This data is the fingerprint of what you’re watching being sent through the Internet to Cognitive Networks. This data is sent regardless of whether you agree to the privacy policy and terms of service when first configuring the TV,” said the researchers.

The data is more like a snapshot of pixels rather than a clear view of what you are watching. Here’s an example from Avast. Vizio has a way of deactivating this tracking through the following commands: Menu -> Reset & Admin -> Smart Interactivity -> OFF.

Avast has dubbed its discovery as a possible attack vector into a person’s home network. It’s just the latest evidence that shows how a smart TV can make your local network vulnerable, and Avast claims that it could be a possible means to display content remotely on someone else’s TV.

“Further investigation is needed to demonstrate a proof of concept; however, this appears to be a potential attack vector for remotely displaying unwanted material on a person’s TV,” said Avast.

Vizio has patched these vulnerabilities and says the update will install automatically, but there is still no report on whether this update has been successfully delivered to all TV owners yet.

Jonathan Keane
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
AI slop stories are spoiling the childhood
Grandparents are gifting AI-generated story books to kids, and it's just gross.
A child reading a book.

AI slop, the colloquial term for low-effort AI-generated content, has emerged as a huge problem across different industries. Music labels are fighting streaming services to put an AI label on such tra/cks. Publishing houses are wary of AI-written drafts. Research journals are buried under a deluge of AI-generated papers. The software industry is reeling under the pressure of vibe-coded apps brimming with security flaws. Even Apple is struggling against a tide of bug reports created using AI. Of course, the disdain against AI is pretty obvious, but there's now a new dimension to it.

Boomers are gifting AI-generated books to their grandkids.

Read more
The MacBook Air is running in short supply, despite a price hike
The memory crunch is now disrupting MacBook Air supplies
MacBook Air M5

For months, Apple seemed better protected from the memory crisis than most laptop makers. It had long-term supplier agreements, enormous purchasing power, and enough margin to absorb rising component costs. The situation has now caught up with its most popular laptop.

According to Bloomberg’s Mark Gurman, MacBook Air availability has tightened considerably across Apple’s retail network. Several configurations are showing delivery estimates stretching into late August, while some customized models may not arrive until September.

Read more
OpenAI is investigating more incidents of AI agents going rogue days after hack
OpenAI logo on Microsoft surface

It appears that the "AI agents going rogue" tale has more to it than what AI giants have revealed publicly so far. Merely days after OpenAI announced that its AI agents went rogue and hacked Hugging Face, Anthropic dropped a similar bombshell. Soon, it was discovered that not just one, but multiple services were compromised. Well, it seems there are even more layers to it.

Reuters reports that OpenAI has found more incidents of AI agents escaping their software containment environment during research. Citing sources with knowledge of the incident, the outlet notes that the AI agents didn't go beyond OpenAI's software environment and affect any external service.

Read more