Back to news

Azure Cosmos DB Patch Closes Tenant-Wide Key Leak; LG Bans Proxy Apps from Smart TVs

Two separate disclosures this week expose how cloud infrastructure and consumer hardware can become unexpected vectors for large-scale data exposure and network abuse.

Azure Cosmos DB Patch Closes Tenant-Wide Key Leak; LG Bans Proxy Apps from Smart TVs

What happened

Security firm Wiz disclosed a now-patched vulnerability chain in Microsoft Azure Cosmos DB, dubbed CosmosEscape, that allowed an attacker to break out of the service's Gremlin query sandbox using a specially crafted query. Successful exploitation yielded code execution on underlying infrastructure and ultimately exposed a platform-wide key granting full read and write access to databases across multiple customer tenants — not just the attacker's own account. Separately, LG Electronics USA announced it will suspend any webOS smart TV applications found to be functioning as residential proxy nodes, routing third-party internet traffic through consumers' home networks without meaningful disclosure. The move follows researcher findings that over 42 percent of apps in LG's webOS store contained this behavior.

Why it matters for your business

The Cosmos DB flaw is a stark reminder that multi-tenant cloud databases carry cross-customer risk; a single compromised account or malicious query could have compromised data belonging to entirely unrelated organizations. Enterprises relying on managed cloud databases should verify with vendors that sandbox isolation is regularly penetration-tested and that any platform-level credential rotation occurred following disclosure. The LG proxy issue is relevant to any organization with smart TVs on corporate or guest networks: devices running rogue proxy software can be used to launder malicious traffic, complicate threat attribution, and consume bandwidth. Network administrators should treat smart TVs and other consumer IoT devices as untrusted endpoints and segment them accordingly.

What to watch next

Microsoft has patched the Cosmos DB flaw, but security teams should monitor for any follow-on disclosures about whether the platform-wide key was accessed prior to remediation, as Wiz has not confirmed exploitation in the wild. On the LG front, watch whether other smart TV and streaming platform vendors — Roku, Samsung, Amazon — face similar scrutiny over their app vetting processes, given how rarely consumer device app stores are audited for network-abusing SDK behavior. Regulatory interest in residential proxy networks embedded in consumer electronics is also growing, which could accelerate mandatory disclosure requirements.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp