{"id":116985,"date":"2019-01-07T18:47:06","date_gmt":"2019-01-07T18:47:06","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=116985"},"modified":"2025-07-01T22:33:12","modified_gmt":"2025-07-02T05:33:12","slug":"google-chromecast-security","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/google-chromecast-security\/","title":{"rendered":"Google Chromecasts: The vulnerabilities you need to know about"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-116989\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2019\/01\/Google-Chromecast-1024x576.jpg\" alt=\"Google Chromecast streaming dongle\" width=\"840\" height=\"473\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Google-Chromecast-1024x576.jpg 1024w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Google-Chromecast-300x169.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Google-Chromecast-768x433.jpg 768w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Google-Chromecast-800x450.jpg 800w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Google-Chromecast-664x374.jpg 664w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Google-Chromecast-238x134.jpg 238w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Google-Chromecast-436x246.jpg 436w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Google-Chromecast-370x208.jpg 370w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Google-Chromecast-304x170.jpg 304w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Google-Chromecast-1200x675.jpg 1200w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Google-Chromecast.jpg 1280w\" sizes=\"auto, (max-width: 840px) 100vw, 840px\" \/><\/p>\n<p>Google Chromecasts are interesting little things. Tiny hockey puck-like dongles that enable you to hook up your TVs and stereos to your home Wi-Fi network. This means you can hook them up to your mobile devices, which means you can have the movies or music on your phone playing on your big TV or blasting out your big speakers. They don\u2019t grab the headlines like smart speakers do, but they have proven rather popular and there will be lots of us who received a Chromecast over the holidays.<\/p>\n<div class=\"sc-card-starred-link\">\r\n  <div class=\"sc-card-starred-link__body\">\r\n    <div class=\"sc-card-starred-link__row clearfix\">\r\n      <div class=\"sc-card-starred-link__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-starred-link__img\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/05\/netflix.jpg\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-starred-link__col-title\">\r\n        <p class=\"sc-card-starred-link__title\">The 5 best sites for streaming recommendations<\/p>\r\n        <a class=\"sc-card-starred-link__button\" href=\"https:\/\/en.softonic.com\/articles\/the-5-best-sites-for-streaming-recommendations\" target=\"_blank\" rel=\"noopener noreferrer sponsored\">Find a better movie now<\/a>\r\n      <\/div>\r\n    <\/div>\r\n    <a class=\"sc-card-starred-link__link\" href=\"https:\/\/en.softonic.com\/articles\/the-5-best-sites-for-streaming-recommendations\" target=\"_blank\" rel=\"noopener noreferrer sponsored\"><\/a>\r\n  <\/div>\r\n<\/div>\n<p>Just like any device that connect to the internet, <strong>Chromecasts are vulnerable to being compromised by malware.<\/strong> As it is important for us to know about all of the vulnerabilities that affect us, a move by hackers known as <a href=\"https:\/\/twitter.com\/hackergiraffe?lang=en\" target=\"_blank\" rel=\"noopener noreferrer\">Hacker<\/a>, <a href=\"https:\/\/twitter.com\/hackergiraffe?lang=en\" target=\"_blank\" rel=\"noopener noreferrer\">Giraffe<\/a>, and <a href=\"https:\/\/twitter.com\/j3ws3r\" target=\"_blank\" rel=\"noopener noreferrer\">J3ws3r<\/a> could be seen as public service. Although others might not see it that way.<\/p>\n<h2>Hackers have hijacked thousands of Google Chromecasts to highlight security vulnerabilities<\/h2>\n<p>According to <a href=\"https:\/\/techcrunch.com\/2019\/01\/02\/chromecast-bug-hackers-havoc\/\" target=\"_blank\" rel=\"noopener noreferrer\">a report by TechCrunch<\/a>, the three hackers figured out how to make Google Chromecasts play any YouTube video they want. They even found a way to play custom-made videos, too. Of course, upon discovering the vulnerability, they immediately exploited it to make sure that users knew about the flaw in their online security efforts.<\/p>\n<p>Thousands of Chromecast owners were shown a pop-up that warned them of their weakness. The message (shown below) highlighted the users\u2019 misconfigured routers as the culprits and warned that other hackers would also be able to exploit the weakness and break in, too. They also asked users to subscribe to and follow YouTube personality PewDiePie\u2019s channels.<\/p>\n<figure id=\"attachment_116988\" aria-describedby=\"caption-attachment-116988\" style=\"width: 700px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-116988\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2019\/01\/Chromecast-hack-screenshot-300x168.jpg\" alt=\"\" width=\"700\" height=\"393\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Chromecast-hack-screenshot-300x169.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Chromecast-hack-screenshot-768x431.jpg 768w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Chromecast-hack-screenshot-1024x575.jpg 1024w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Chromecast-hack-screenshot-800x450.jpg 800w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Chromecast-hack-screenshot-664x374.jpg 664w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Chromecast-hack-screenshot-238x134.jpg 238w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Chromecast-hack-screenshot-436x246.jpg 436w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Chromecast-hack-screenshot-370x208.jpg 370w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Chromecast-hack-screenshot-304x170.jpg 304w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2019\/01\/Chromecast-hack-screenshot-1200x674.jpg 1200w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><figcaption id=\"caption-attachment-116988\" class=\"wp-caption-text\">Image via: <a href=\"https:\/\/techcrunch.com\/2019\/01\/02\/chromecast-bug-hackers-havoc\/\" target=\"_blank\" rel=\"noopener noreferrer\">TechCrunch<\/a><\/figcaption><\/figure>\n<p>Google responded to the hack by saying the problem lay elsewhere and was not in the Chromecasts themselves. Speaking to TechCrunch, a Google Spokesperson said, \u201cWe have received reports from users who have had an unauthorized video played on their TVs via a Chromecast device\u2026 This is not an issue with Chromecast specifically, but is rather the result of router settings that make smart devices, including Chromecast, publicly reachable.\u201d<\/p>\n<p>The bug, known as CastHack, isn\u2019t a new one and has been plaguing these types of devices since 2014. Whereas Google is right in saying that the vulnerability lays outside of its product, it is also true that hackers can use Google products to gain a foothold in users\u2019 homes. With the problem going back four years, Google really should have fixed the bug by now.<\/p>\n<div class=\"sc-card-starred-link\">\r\n  <div class=\"sc-card-starred-link__body\">\r\n    <div class=\"sc-card-starred-link__row clearfix\">\r\n      <div class=\"sc-card-starred-link__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-starred-link__img\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2017\/09\/Chrome-Decurity-192.jpg\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-starred-link__col-title\">\r\n        <p class=\"sc-card-starred-link__title\">8 tricks to boost your security on Google Chrome<\/p>\r\n        <a class=\"sc-card-starred-link__button\" href=\"https:\/\/en.softonic.com\/articles\/8-tricks-to-boost-your-security-on-google-chrome\" target=\"_blank\" rel=\"noopener noreferrer sponsored\">Boost your security now<\/a>\r\n      <\/div>\r\n    <\/div>\r\n    <a class=\"sc-card-starred-link__link\" href=\"https:\/\/en.softonic.com\/articles\/8-tricks-to-boost-your-security-on-google-chrome\" target=\"_blank\" rel=\"noopener noreferrer sponsored\"><\/a>\r\n  <\/div>\r\n<\/div>\n<p>Although the idea of playing videos on a screen might not seem like a huge problem on its own, the rapid expansion of the <a href=\"http:\/\/en.softonic.com\/articles\/iot-and-the-smart-home\/\" target=\"_blank\" rel=\"noopener noreferrer\">smart home industry<\/a>, centered around smart speakers, opens up some chilling possibilities. If a hacked Chromecast can be made to say things like, \u201cTurn off the house alarm\u201d or to \u201cBuy something from Amazon,\u201d then all of a sudden, this problem can hit you in the wallet or even put your physical safety in jeopardy.<\/p>\n<!-- Shortcode [playwire] does not match the conditions -->\n","protected":false},"excerpt":{"rendered":"<p>Hackers have hijacked thousands of Google Chromecasts to highlight security vulnerabilities.<\/p>\n","protected":false},"author":9073,"featured_media":116989,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[2340,1030,1032,1068,1039,1027],"usertag":[839],"vertical":[],"content-category":[],"class_list":["post-116985","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectiongoogle","tag-entertainment","tag-gadgets","tag-google","tag-multimedia","tag-security","usertag-vpn"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/116985","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9073"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=116985"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/116985\/revisions"}],"predecessor-version":[{"id":326801,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/116985\/revisions\/326801"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/116989"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=116985"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=116985"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=116985"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=116985"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=116985"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=116985"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}