discovered 03 Aug 2026
slopbro
→ View on GitHubSlopBro is a proof-of-concept exploit designed to leverage the jsserver vulnerability in LG TVs running webOS versions 5 to 10. It operates by starting an HTTP server to deliver an exploit page and payloads, establishing an SSAP connection with the target TV, and executing a rogue package with root privileges, allowing for potential persistence and the installation of additional software like the Homebrew Channel. Notable features include compatibility across Python 2.7 and 3.x, minimal dependency requirements, and options for debugging and asset source specification.