Hackers Hijack Thousands of Chromecasts to Expose Router Flaw
Hackers known as Hacker Giraffe and J3ws3r hijack thousands of Chromecast devices to display security warnings and promote a YouTube channel. The exploit relies on misconfigured router settings that leave the streaming devices vulnerable to unauthenticated takeovers.
Hackers known as Hacker Giraffe and J3ws3r hijack thousands of exposed Chromecast devices to play custom YouTube videos on users' TVs. The attackers use this exploit, dubbed CastHack, to display a pop-up warning that advises victims about their misconfigured routers while simultaneously asking them to subscribe to the popular PewDiePie YouTube channel. Google confirms that it receives reports of these unauthorized video streams but claims the issue stems directly from router settings rather than a flaw in the Chromecast itself.
The exploit works by taking advantage of routers that have Universal Plug and Play (UPnP) enabled, which inadvertently makes smart devices publicly reachable on the internet. Although the hackers suggest that disabling UPnP fixes the problem, other security experts dispute this claim. The core issue remains that the Chromecast allows an unauthenticated attacker to hijack a media stream and force the device to display whatever content they choose.
This type of vulnerability is unfortunately not a new discovery for the streaming device. Security firm Bishop Fox first uncovered a similar hijacking bug in 2014, demonstrating that attackers could disconnect a Chromecast from Wi-Fi to force it into an out-of-the-box state waiting for instructions. Later, in 2016, cybersecurity firm Pen Test Partners discovers that the device is still vulnerable to these deauth attacks, proving that the underlying security flaw persists across multiple hardware generations.