Skip to content
The Executives BriefThe Executives BriefBeta

Microsoft and Windows users caught LG installing McAfee ads via Windows Update

LG monitor software piggybacks on Windows Update, then surfaces McAfee free-trial pop-ups, prompting a quick public backlash and response.

ByLama Al-RashidTechnology Correspondent, The Executives Brief
·3 min read
Microsoft and Windows users caught LG installing McAfee ads via Windows Update
Executive summary

Microsoft operating systems are at the center of a dispute after LG monitors used an installer called LG Monitor App Installer to push ads for a 30-day McAfee free trial. The consequence for decision-makers is a fresh reminder that device firmware and update channels can reach deep into endpoints.

LG is reportedly pulling a McAfee pop-up ad from a controversial app that some of its monitors stealthily installed on computers once those monitors connected. The software in question is LG Monitor App Installer, and the core issue is not a weird standalone browser scam. It is an installer that rides along with normal system maintenance, showing up through Windows Update.

Multiple users have reported that when certain LG monitors connect, LG Monitor App Installer is installed via Windows Update alongside monitor driver updates. After that, it reportedly pushes ads for a 30-day free trial for McAfee, plus other software, using a pop-up on affected systems. In other words, the “ad” is arriving through the same pipeline people assume is boring and safe: Windows Update.

The negative attention escalated enough to move beyond isolated complaints. Ars Technica reports the controversy drew criticism after complaints surfaced on Reddit and after a video from YouTube channel Gamers Nexus. In that coverage, editor-in-chief Steve Burke said the publication paid $1,200 for an LG UltraGear 3GX900A-B gaming monitor for testing, and that the monitor’s price dropped to $600 two days later, a detail Burke shared while describing the experiment. He also said the team replicated the behavior “several times” across “multiple” Windows 11 systems.

This is where the story stops being “annoying pop-ups” and starts looking like an endpoint trust problem. Windows Update is typically the channel executives and IT teams treat as a controlled distribution path. Driver and firmware updates are routine. But this case suggests that monitor companion software, even when delivered through the Windows Update mechanism, can change what users see and what applications appear, including marketing flows that users might never have explicitly agreed to. That distinction matters because the decision-making surface is different. Users click through the monitor purchase. IT teams approve update policies. The ad, however, lands on the endpoint after the connection.

From a governance and risk perspective, this is a classic incentive mismatch. Device makers want to monetize companion experiences and bundle software. Meanwhile, enterprises and regulators focus on transparency, consent, and the boundaries of what “update” is allowed to do. When a third-party app installer piggybacks on driver delivery, it can blur those boundaries for both users and security teams. Even if the underlying marketing is technically “installed,” the experience looks like unwanted software delivery inside a familiar update lane.

The fact pattern also highlights how quickly public testing can turn a vendor-side policy decision into an industry-wide reputational issue. Gamers Nexus did not just point at a screenshot. Burke said the behavior was replicated “several times” across “multiple” Windows 11 systems. Reports described a pop-up offering a McAfee 30-day free trial. That is specific enough for security teams to investigate and specific enough for watchdog attention to spread. In that environment, any response needs to be faster than the rumor cycle, because the next step for many organizations is immediate triage: isolate affected devices, audit update logs, and check whether any installer components were delivered beyond drivers.

Second-order implications are bigger than this one monitor model, too. If monitor add-ons can install adware-like experiences via Windows Update alongside driver updates, then the “attack surface” executives worry about expands in a subtle direction. It becomes not only about what runs on servers or what ships in apps, but also about what gets deployed when a peripheral is plugged in and a driver update triggers. Boards and CISOs tend to plan for traditional vectors like phishing or malicious downloads. This is different. It is “connected device to endpoint” distribution, which can bypass the user’s active decision to install software.

For peers, the strategic lesson is straightforward: endpoint risk is increasingly supply-chain and peripheral driven, not just application driven. LG is reportedly pulling a McAfee pop-up from the LG Monitor App Installer flow, but the broader takeaway is about controls and visibility. If Windows Update delivery can include companion installers that then advertise a third-party security brand via pop-ups, then both vendors and enterprises need to tighten expectations around what counts as a driver update and how software bundling is disclosed. In the meantime, for decision-makers, the operational question becomes: can you confidently audit what installed when a device connected, and can you prevent “updates” from turning into marketing events on corporate machines?

Executive ActionsLocked

This story's Key Insights and Take-aways are locked.

Create a free account to unlock Executive Actions for one credit.

Register to Unlock

Always free for Executives Club members. Join the Club

More in Technology