Close Menu
Ztoog
    What's Hot
    Technology

    Best TV Deals: Up to $1,000 in Discounts on LG, Samsung, Fire TV and More

    Gadgets

    Unreleased preview of Microsoft’s OS/2 2.0 is a glimpse down a road not taken

    The Future

    Optimizing AI for Seamless and Simplified Payment Processing

    Important Pages:
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    Facebook X (Twitter) Instagram Pinterest
    Facebook X (Twitter) Instagram Pinterest
    Ztoog
    • Home
    • The Future

      What is Project Management? 5 Best Tools that You Can Try

      Operational excellence strategy and continuous improvement

      Hannah Fry: AI isn’t as powerful as we think

      FanDuel goes all in on responsible gaming push with new Play with a Plan campaign

      Gettyimages.com Is the Best Website on the Internet Right Now

    • Technology

      Iran war: How could it end?

      Democratic senators question CFTC staffing cuts in Chicago enforcement office

      Google’s Cloud AI lead on the three frontiers of model capability

      AMD agrees to backstop a $300M loan from Goldman Sachs for Crusoe to buy AMD AI chips, the first known case of AMD chips used as debt collateral (The Information)

      Productivity apps failed me when I needed them most

    • Gadgets

      macOS Tahoe 26.3.1 update will “upgrade” your M5’s CPU to new “super” cores

      Lenovo Shows Off a ThinkBook Modular AI PC Concept With Swappable Ports and Detachable Displays at MWC 2026

      POCO M8 Review: The Ultimate Budget Smartphone With Some Cons

      The Mission: Impossible of SSDs has arrived with a fingerprint lock

      6 Best Phones With Headphone Jacks (2026), Tested and Reviewed

    • Mobile

      Android’s March update is all about finding people, apps, and your missing bags

      Watch Xiaomi’s global launch event live here

      Our poll shows what buyers actually care about in new smartphones (Hint: it’s not AI)

      Is Strava down for you? You’re not alone

      The Motorola Razr FIFA World Cup 2026 Edition was literally just unveiled, and Verizon is already giving them away

    • Science

      Big Tech Signs White House Data Center Pledge With Good Optics and Little Substance

      Inside the best dark matter detector ever built

      NASA’s Artemis moon exploration programme is getting a major makeover

      Scientists crack the case of “screeching” Scotch tape

      Blue-faced, puffy-lipped monkey scores a rare conservation win

    • AI

      Online harassment is entering its AI era

      Meet NullClaw: The 678 KB Zig AI Agent Framework Running on 1 MB RAM and Booting in Two Milliseconds

      New method could increase LLM training efficiency | Ztoog

      The human work behind humanoid robots is being hidden

      NVIDIA Releases DreamDojo: An Open-Source Robot World Model Trained on 44,711 Hours of Real-World Human Video Data

    • Crypto

      SEC Vs. Justin Sun Case Ends In $10M Settlement

      Google paid startup Form Energy $1B for its massive 100-hour battery

      Ethereum Breakout Alert: Corrective Channel Flip Sparks Impulsive Wave

      Show Your ID Or No Deal

      Jane Street sued for alleged front-running trades that accelerated Terraform Labs meltdown

    Ztoog
    Home » Android TV has access to your entire account—but Google is changing that
    Gadgets

    Android TV has access to your entire account—but Google is changing that

    Facebook Twitter Pinterest WhatsApp
    Android TV has access to your entire account—but Google is changing that
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp

    Google

    Google says it has patched a nasty loophole within the Android TV account safety system, which might grant attackers with bodily access to your machine access to your entire Google account simply by sideloading some apps. As 404 Media stories, the problem was initially introduced to Google’s consideration by US Sen. Ron Wyden (D-Ore.) as a part of a “overview of the privateness practices of streaming TV expertise suppliers.” Google initially advised the senator that the problem was anticipated habits however, after media protection, determined to change its stance and situation some sort of patch.

    “My workplace is mid-way via a overview of the privateness practices of streaming TV expertise suppliers,” Wyden advised 404 Media. “As a part of that inquiry, my workers found an alarming video during which a YouTuber demonstrated how with quarter-hour of unsupervised access to an Android TV set-top field, a prison may get access to personal emails of the Gmail person who arrange the TV.”

    The video in query was a PSA from YouTuber Cameron Gray, and it exhibits that grabbing any Android TV machine and sideloading a number of apps will grant access to the present Google account. This is apparent if you understand how Android works, however it’s not apparent to most customers taking a look at a restricted TV interface.

    The coronary heart of the problem is how Android treats your Google account. Since the OS began on telephones, each Android machine begins with the idea that it is a non-public, one-person machine. Google has constructed on prime of that function with multiuser assist and visitor accounts, however these aren’t a part of the default setup move, might be laborious to discover, and are most likely disabled on many Android TV containers. The end result is that signing in to an Android TV machine usually provides it access to your entire Google account.

    Advertisement

    Android has a centralized Google account system shared by one million Google-centric background and syncing processes, the Play Store, and almost all Google apps. When you boot an Android machine for the primary time, the guided setup asks for a Google account, which is anticipated to reside on the machine perpetually because the proprietor’s major account. Any new Google app you add to your machine robotically will get access to this central Google account repository, so in the event you arrange the telephone after which set up Google Keep, Keep robotically will get signed in and features access to your notes. During the preliminary setup, the place you would possibly set up 10 totally different apps that use a Google account, it might be annoying to enter your username and password time and again.

    This centralized account system is hungry for Google accounts, so any Google account you employ to sign up to any Google app will get sucked into the central account system, even in the event you decline the preliminary setup. A typical annoyance is to have a Google Workspace account at work, then signal into Gmail for work e mail after which have to take care of this ineffective work account exhibiting up within the Play Store, Maps, Photos, and many others.

    For TVs, this presents a singular gotcha as a result of, whereas you’ll nonetheless be pressured to log in to obtain one thing from the Play Store, it isn’t apparent to the person that you are granting this machine access to your entire Google account—together with to doubtlessly delicate issues like location historical past, emails, and messages. To the typical person, a TV machine simply exhibits “TV stuff” like your YouTube suggestions and some TV-specific Play Store apps, so that you may not think about it to be a high-sensitivity sign-in. But in the event you simply sideload a number of extra Google apps, you may get access to something. Further complicated issues is Google’s OAuth technique, which teaches customers that there are issues like scoped access to a Google account on third-party gadgets or websites, however Android doesn’t work that means.

    Advertisement

    In the video, Gray merely grabs an Android TV machine, goes to a third-party Android app web site, then sideloads Chrome. Chrome robotically indicators in to the TV proprietor’s Google account and has access to all passwords and cookies, which suggests access to Gmail, Photos, Chat historical past, Drive information, YouTube accounts, AdvertSense, any web site that permits for Google sign-in, and partial bank card data. It’s all obtainable in Chrome with none safety checks. Individual apps like Gmail and Google Photos would instantly begin working, too.

    As Gray’s video factors out, Android TV gadgets might be dongles, set-top containers, or code put in proper right into a TV. In companies and motels, they are often semi-public gadgets. It’s additionally not laborious to think about a TV machine falling into the arms of another person. You may not fear an excessive amount of about forgetting a $30 Chromecast in a lodge room, otherwise you would possibly sign up to a lodge TV and neglect to delete your account, otherwise you would possibly throw out a TV and never assume twice about what account it is signed in to. If an attacker will get access to any of those gadgets later, it is trivial to unlock your entire Google account.

    Google says it has mounted this downside, although it would not clarify how. The firm’s assertion to 404 says, “Most Google TV gadgets operating the most recent variations of software program already don’t enable this depicted habits. We are within the strategy of rolling out a repair to the remainder of the gadgets. As a finest safety observe, we at all times advise customers to replace their gadgets to the most recent software program.”

    Many Android TV gadgets, particularly these built-in to TV units, are abandonware and run an previous model of the software program, however Google’s account system is updatable through the Play Store, so there is a good likelihood a repair can roll out to most gadgets.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp

    Related Posts

    Gadgets

    macOS Tahoe 26.3.1 update will “upgrade” your M5’s CPU to new “super” cores

    Gadgets

    Lenovo Shows Off a ThinkBook Modular AI PC Concept With Swappable Ports and Detachable Displays at MWC 2026

    Gadgets

    POCO M8 Review: The Ultimate Budget Smartphone With Some Cons

    Gadgets

    The Mission: Impossible of SSDs has arrived with a fingerprint lock

    Gadgets

    6 Best Phones With Headphone Jacks (2026), Tested and Reviewed

    Gadgets

    5 changes to know about in Apple’s latest iOS, macOS, and iPadOS betas

    Gadgets

    Lenovo Unveils AI-Enhanced Legion Y700 (2026): A New Benchmark For Compact Gaming Tablets

    Gadgets

    ASUS Vivobook S16 OLED Review: The Most Practical 16-inch Laptop Right Now

    Leave A Reply Cancel Reply

    Follow Us
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    Top Posts
    Science

    Why Are We Seeing These Crazy Northern Lights?

    The aurora borealis is often seen solely means up north, however two weeks in the…

    Crypto

    Coinbase’s Q3 revenue beat expectations, but its shares fell as growth prospects underwhelmed

    Coinbase, the second-largest crypto alternate by buying and selling quantity, launched its Q3 2023 earnings…

    Technology

    Structural Evolutions in Data – O’Reilly

    I’m wired to consistently ask “what’s next?” Sometimes, the reply is: “more of the same.” That…

    Science

    An Ancient Egyptian Pigment, the Next Energy-Saving Solution

    Sometimes you don’t must resort to stylish labs to search out options for power challenges…

    Mobile

    Samsung Galaxy S24 Ultra design revealed through CAD renders

    Right after the Galaxy S24’s design was revealed by SmartPrix in collaboration with @OnLeaks, it…

    Our Picks
    Gadgets

    Android phone hits 24GB of RAM, as much as a 13-inch MacBook Pro

    AI

    University of Cambridge Researchers Introduce a Dataset of 50,000 Synthetic and Photorealistic Foot Images along with a Novel AI Library for Foot

    AI

    Meet Microsoft’s Open-Sourced KubeAI Application Nucleus: A Solution Accelerator for Creating, Deploying, and Operating Environment-Aware Solutions at Scale that Use Artificial Intelligence (AI) at the Edge

    Categories
    • AI (1,560)
    • Crypto (1,827)
    • Gadgets (1,870)
    • Mobile (1,910)
    • Science (1,939)
    • Technology (1,862)
    • The Future (1,716)
    Most Popular
    Gadgets

    Apple’s cheaper Pencil is available to buy now, but it has some limitations

    The Future

    The Tesla Cybertruck Rolls Off the Line

    The Future

    Mark Zuckerberg: Meta wants to create artificial general intelligence

    Ztoog
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    © 2026 Ztoog.

    Type above and press Enter to search. Press Esc to cancel.