LG Monitors Silently Install Windows App and McAfee Software Without User Consent: Security Risk
A newly highlighted privacy and security concern involving LG monitors has raised questions about how Windows handles companion software installations for connected hardware.
Testing conducted by CyberDigest found that several LG monitor models automatically trigger the installation of the LG Monitor App Installer immediately after being connected to a Windows PC.
The installation occurs silently through Windows Update without displaying a permission prompt, confirmation dialog, or user approval request.
The first visible indication for many users is a pop-up promoting a 30-day free trial of McAfee, leaving users unaware that new software has already been installed on their systems.
LG Monitors Silently Install Windows App
According to the findings, connecting an LG UltraGear monitor to a Windows computer initiates the installation within approximately one minute.
Windows Reliability Monitor records the event shortly after the display cable is connected, confirming that the installation is delivered automatically through Microsoft’s trusted update infrastructure.
Because the process is handled by Windows rather than a traditional installer, users receive no warning or notification before the application appears on their devices.
Security researchers argue that while the mechanism itself is legitimate, its implementation in this scenario raises significant concerns about user consent and software transparency.
The LG Monitor App Installer’s permissions have become a major focus of the investigation. Information available through the Microsoft Store indicates that the application requests access to all system resources in addition to the device’s internet connection.
While these permissions may support hardware management features, cybersecurity experts note that such extensive access should be accompanied by explicit user authorization.
Broad permission scopes increase the potential impact if vulnerabilities are discovered or if the application performs functions beyond its advertised purpose.
Further analysis by Notebookcheck identified the affected hardware as the LG UltraGear 34GX900A-B and reported that the installation package also deploys a McAfee Scam Detector component.
LG’s own installer documentation reportedly references access to various categories of information, including hardware configuration, device location, online activity, account-related information, and contacts.
Although researchers did not observe evidence that sensitive data was actively transmitted, they emphasized that software possessing extensive permissions and internet connectivity could theoretically collect or transmit information if its functionality changed through future updates.
Gamers Nexus independently reproduced the behavior and observed that the McAfee trial offer appeared during most system startups after installation.
In some instances, additional recommendations for LG-related software were also presented. While these promotions do not indicate malicious activity, cybersecurity professionals argue that advertisements delivered through automatically installed software reduce user trust and blur the line between legitimate device management utilities and unwanted applications.
CyberDigest’s broader testing revealed that the behavior is not limited to a single monitor model. The automatic installation occurred across multiple LG UltraGear and UltraFine displays, including products released nearly three years ago.
Researchers observed the software appearing in 31 out of 32 boot tests, suggesting the deployment mechanism has existed for an extended period and affects both newly purchased and previously installed hardware. At the time of reporting, LG had not publicly responded to the findings or clarified the intended purpose of the installation process.
The software delivery relies on Windows’ Device Metadata Retrieval Client, a Microsoft feature designed to automatically install companion applications associated with connected hardware.
The technology was originally intended to simplify driver installation, firmware updates, and device management utilities.
However, because installations occur silently in the background without user interaction, security researchers believe the mechanism should be reserved for essential hardware functionality rather than promotional software or applications requesting extensive permissions.
Users concerned about the behavior can take several mitigation steps. Windows Pro and Enterprise users can disable automatic installation of device-associated applications by opening Group Policy Editor (gpedit.msc) and navigating to Computer Configuration → Administrative Templates → System → Device Installation, then enabling “Prevent automatic download of applications associated with device metadata.”
Windows Home users can instead modify the Windows Registry or adjust Microsoft Store download settings to reduce automatic app installations.
Users should also review Settings → Apps and uninstall both the LG Monitor App Installer and McAfee Scam Detector if they do not require these applications.
The incident highlights the importance of transparency, user consent, and stricter oversight of software delivered through trusted operating system update mechanisms.
No Comment! Be the first one.