Researchers from KU Leuven have identified a widespread issue where embedded web browsers in devices such as smart TVs, e-readers, game consoles, and cars are significantly outdated compared to their desktop and mobile counterparts. Using a crowdsourced evaluation framework called CheckEngine, the study found that many newly released devices ship with browsers that are several years behind in security updates, exposing users to known vulnerabilities and phishing risks. In some cases, manufacturers do not provide timely security updates for these browsers, despite advertising ongoing support.
The research, presented at the USENIX Symposium on Usable Privacy and Security (SOUPS) 2025, analyzed 53 unique products and 68 software versions, revealing that 24 out of 35 smart TVs and all 5 e-readers tested had browsers at least three years out of date. The findings highlight a critical gap in the security maintenance of embedded browsers, which can leave consumers exposed to cyber threats even on brand-new devices. The lack of regular updates and the presence of obsolete browsers at launch underscore the need for improved security practices in the embedded device ecosystem.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Using the crowdsourced CheckEngine framework, the researchers documented cases including the Boox Note Air 3 tablet and platforms such as Steam, Ubisoft Connect, and AMD Adrenalin, where outdated browsers remained in use. The study also found that vendors often failed to deliver timely security updates despite advertising update support, prompting calls for stronger regulatory action.
Researchers from KU Leuven's DistriNet Research Unit found that embedded browsers in products such as smart TVs, e-readers, gaming applications, and cars were often years out of date and exposed to known vulnerabilities. Their analysis showed that even newly released devices frequently shipped with obsolete browser components, increasing risks such as phishing and privilege escalation.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.