News thumbnail
Technology / Tue, 08 Sep 2026 LinkedIn

LG Smart TV Flaws Turn Televisions Into Covert Listening Devices—Even While In Standby

It does not, by itself, prove that every LG television routinely records ambient conversations during ordinary use. Researchers Demonstrate Standby-Mode Audio CaptureThe most serious part of the investigation concerned the microphones built into some LG televisions and remote controls. The findings do not establish that LG intentionally designed its televisions to operate as covert listening devices. Smart TVs Were Seen Mapping the Local NetworkThe investigation also found that tested LG televisions communicated with and collected information about other devices and wireless networks in their environment. On LG televisions, ACR-related functionality has commonly been associated with a feature called Live Plus.

A new technical investigation into LG smart televisions has raised serious privacy and cybersecurity concerns after researchers demonstrated that compromised sets could record nearby conversations, retain captured audio while offline, and transmit the information once an internet connection was restored.

The research, conducted by Gamers Nexus in collaboration with Level1Techs and independent security specialists, examined retail LG OLED televisions, including the G5. Its findings suggest that the security implications of a compromised smart TV extend far beyond viewing-history collection: a vulnerable television could potentially become a persistent surveillance device and a foothold for attacks against other systems on the same network.

The investigation also examined LG’s built-in data-collection and advertising technologies. Researchers reported that the televisions performed extensive discovery of devices and wireless networks in their surroundings, gathering information that could help construct a detailed picture of a household’s digital environment.

However, an important distinction must be made between the television’s standard commercial features and the behavior researchers achieved after gaining elevated access to the device. The demonstration of continuous audio surveillance appears to have depended on exploiting security weaknesses or otherwise obtaining privileged control. It does not, by itself, prove that every LG television routinely records ambient conversations during ordinary use.

LG has previously said that its televisions do not collect, record or store ambient conversations and that voice recognition is an optional feature activated by the user. The newly reported vulnerabilities challenge the security assumptions behind that position because an attacker who compromises the operating system may no longer be bound by the controls and restrictions governing normal voice-recognition functions.

Full technical details of the reported vulnerabilities have not been released while responsible disclosure is underway. As of the investigation’s publication, no public vulnerability identifiers had been cited for the new flaws, and the precise range of affected webOS versions and television models remained unclear.

Researchers Demonstrate Standby-Mode Audio Capture

The most serious part of the investigation concerned the microphones built into some LG televisions and remote controls.

Researchers demonstrated that after compromising a television, they could access its audio capabilities and collect nearby speech even when the screen was off and the device appeared to be in standby. This is significant because consumers typically understand a dark screen to mean that a television is inactive, even though many smart televisions maintain network connectivity and continue running background services while waiting for remote-control, voice-assistant, casting or software-update commands.

Modern televisions rarely power down completely when switched off using a remote. Instead, they usually enter a low-power state that allows selected processors and services to remain available. Features such as “quick start,” wake-on-network functionality, mobile-app control, voice activation and scheduled updates may require parts of the television’s operating system to continue running.

That architecture can create an opportunity for attackers if a software vulnerability gives them control over a service that remains active during standby.

According to the researchers, audio could also be retained locally when the television was disconnected from the internet. Once connectivity returned, the captured material could be retrieved or transmitted. This store-and-forward capability would reduce the effectiveness of temporarily blocking the television’s internet connection after a compromise, because information collected during the offline period might remain available on the device.

The findings do not establish that LG intentionally designed its televisions to operate as covert listening devices. Rather, they demonstrate what may become possible when a powerful, internet-connected appliance containing microphones, storage and background network services is successfully compromised.

This distinction is critical. Legitimate voice processing generally requires a deliberate user action, such as pressing a microphone button or invoking a voice assistant. Malicious recording, by contrast, would attempt to bypass the expected visual indicators, permission controls and activation requirements.

In a statement issued during an earlier dispute about LG’s voice-recognition terms, the company said its TVs do not collect or store ambient conversations. It said voice recognition was “optional” and processed voice data only after activation to complete a request. That response predated the latest technical findings and addressed intended product behavior rather than what an attacker could do after compromising webOS.

Smart TVs Were Seen Mapping the Local Network

The investigation also found that tested LG televisions communicated with and collected information about other devices and wireless networks in their environment.

Packet captures reportedly showed televisions identifying systems such as smartphones, computers, smartwatches, printers, network switches and connected-home equipment. The sets also gathered internal network addresses and information about nearby Wi-Fi access points, including network names and signal strength.

Some level of local-network discovery can support legitimate television functions. Casting, screen sharing, media streaming, mobile remote-control applications and smart-home integration all depend on discovering compatible devices.

The privacy concern arises from the scale, persistence and commercial use of that discovery. Information about the devices connected to a home network can reveal more than a list of hardware. Device types, identifiers, operating patterns and network relationships can help infer how many people live in a household, which technology platforms they use and when particular devices are active.

When combined with an advertising identifier, an IP address and television-viewing information, this environmental data may help an advertising platform associate activity across multiple screens.

That does not necessarily mean a television is intercepting the private contents of communications travelling between other devices. Network discovery and content interception are technically different activities. Nevertheless, a compromised television located on the same local network as computers and phones could be used to identify possible targets, search for exposed services and support later attempts to move deeper into the network.

This is why security specialists increasingly recommend separating internet-of-things equipment from computers that contain sensitive personal or business information.

The Advertising Business Behind the Screen

The investigation places the technical findings within the broader economics of the smart-TV industry.

Connected televisions have developed into advertising platforms capable of observing what viewers watch across broadcast channels, streaming applications and externally connected equipment. One of the central technologies used for this purpose is automated content recognition, or ACR.

ACR works by sampling selected characteristics of audio or video displayed by the television and transforming them into a compact digital fingerprint. That fingerprint can be compared with reference material to identify a television programme, film, advertisement, game or other content.

Because recognition may operate at the display level, it can potentially identify material arriving through an HDMI-connected cable box, game console or computer—not only programming delivered through an application supplied by the television manufacturer.

The resulting viewing data is valuable to advertisers. It can help measure whether an advertisement reached a household, identify audience interests, connect television exposure with activity on other devices and improve the targeting of future campaigns.

On LG televisions, ACR-related functionality has commonly been associated with a feature called Live Plus. Owners can generally disable it, although menu names and locations vary according to model, webOS release and region.

The researchers’ central concern was not simply that ACR exists. The technology and its advertising purposes are broadly known. Their concern was whether consumers meaningfully understand the amount of information being gathered, the relationship between television data and other household devices, and the extent to which refusing optional agreements affects the functionality of a product they have already purchased.

The phrase “own the glass,” used in material examined during the investigation, illustrates the growing commercial importance of the television screen. Once a manufacturer controls the operating system, home screen, recommendation interface and advertising inventory, it can maintain an ongoing commercial relationship with the viewer long after the hardware sale.

ACR Has Faced Years of Regulatory Scrutiny

Concerns surrounding television-viewing data are not new.

In 2017, Vizio agreed to pay $2.2 million to settle allegations brought by the US Federal Trade Commission and the New Jersey Attorney General. Authorities alleged that software installed on approximately 11 million televisions collected detailed viewing information without consumers’ knowledge or consent.

The settlement required prominent disclosure and affirmative consent for relevant collection and sharing practices. Vizio was also ordered to delete certain previously collected data and establish a comprehensive privacy programme. The FTC described the case as unauthorized tracking of consumers’ viewing histories.

The case established an important principle for the connected-TV market: viewing data can be highly sensitive even when it is not initially labelled with a person’s name. When combined with an IP address, persistent identifier, account information or third-party marketing records, household-level viewing information can become part of a much more revealing profile.

Recent legal challenges have kept that issue alive. Texas authorities have pursued television manufacturers over allegations that ACR systems collected or used viewing information without sufficiently clear consent. Such litigation does not, on its own, prove the allegations against any individual manufacturer, but it reflects growing official concern about how consumers are informed and how much control they genuinely possess.

Privacy risks can be particularly acute when private material is displayed on a television. ACR operates on what reaches the screen, meaning its potential visibility is not necessarily limited to conventional television programmes. Depending on implementation, content cast from a phone, played from a computer or displayed by a security-camera system could fall within the recognition pipeline.

Unreleased Vulnerabilities Create a Serious Unknown

Researchers said they reported remote-code-execution vulnerabilities to LG but withheld the details to give the manufacturer time to investigate and distribute fixes.

Responsible disclosure is necessary because releasing working exploit information before patches become widely available could expose consumers to unnecessary risk. The trade-off is that owners and defenders initially receive limited information about which models are affected, how attacks begin and whether exploitation requires access to the local network.

Several important questions consequently remain unanswered.

It is not yet publicly clear whether the newly reported weaknesses can be exploited directly over the internet, only by a device already connected to the same network, or through malicious content or applications. It is also unclear whether user interaction is required, whether the attack survives a restart and which versions of webOS contain the vulnerable components.

Those details determine the practical level of risk. A vulnerability that requires an attacker to be present on the same Wi-Fi network presents a different threat from a remotely exploitable service exposed to the public internet. Similarly, a flaw that produces temporary application-level access differs substantially from one that grants persistent root control.

The absence of full exploit details should not be mistaken for evidence that the issue is insignificant. Remote code execution means an attacker can cause a device to run unauthorized instructions. Depending on the affected component and its privileges, that access may allow surveillance, credential theft, manipulation of installed applications, interception of data or attacks against other systems.

Uncover full campaigns from one IOC in seconds. Speed up triage, hunting, and response with TI Lookup 👇🏻

LG webOS Has Faced Serious Security Flaws Before

The latest findings are not the first security problems identified in LG’s webOS platform.

In 2024, Bitdefender disclosed four vulnerabilities affecting several versions of webOS. The issues, tracked as CVE-2023-6317 through CVE-2023-6320, included an authorization bypass, privilege escalation and command injection. Researchers found that the flaws could be chained to add a privileged account and ultimately obtain root-level control of vulnerable televisions.

The affected versions spanned webOS 4 through webOS 7 on tested LG models. LG released updates in March 2024 following private disclosure. Bitdefender estimated at the time that more than 91,000 potentially vulnerable devices were exposing an affected service to the internet. Bitdefender’s technical report details the earlier webOS attack chain.

One of those flaws, CVE-2023-6320, involved command injection in a webOS connection-management service. The US National Vulnerability Database describes the vulnerability as allowing commands to be injected through an operating-system parameter.

The 2024 vulnerabilities are separate from the weaknesses discussed in the new investigation. They nevertheless demonstrate why televisions must be treated as general-purpose computing devices rather than passive displays.

A modern smart television includes an operating system, network stack, application environment, browser components, microphones, account credentials and locally stored information. From an attacker’s perspective, it is a network-connected Linux computer that may remain powered for years, receive inconsistent security attention and occupy a trusted position inside a home or workplace.

A Compromised TV Could Become a Network Foothold

Audio surveillance is the most immediately alarming scenario, but the network implications may be equally serious.

A compromised television could scan the local network for file shares, web interfaces, media servers, printers, cameras and other smart devices. It might identify equipment using outdated software or weak authentication and attempt to exploit it.

The risk becomes more consequential in small businesses, hotels, conference rooms, executive offices and remote-working environments. Televisions used for videoconferencing or presentations may share networks with corporate laptops and could be located in rooms where confidential discussions regularly occur.

A television also offers attackers a degree of stealth. Consumers tend to notice unusual behavior on a phone or laptop, but few monitor the outbound connections, running processes or storage activity of a TV. Conventional endpoint-security tools generally cannot be installed on webOS, leaving owners dependent on manufacturer updates and network-level monitoring.

Even after a model stops receiving updates, it may remain in use for many years. The display panel can continue working long after the embedded software platform has reached the end of its supported life, creating a growing mismatch between the physical lifespan of the product and its security lifespan.

What LG TV Owners Should Do

Owners should first install the latest available firmware through the television’s software-update menu and verify that automatic updates are enabled. Because the newly disclosed vulnerabilities have not yet been documented publicly, users should continue checking LG’s support page for model-specific updates.

Privacy and user-agreement settings should also be reviewed individually. Disabling Live Plus, viewing-information collection, personalized advertising and voice-recognition functions can reduce routine data collection, although the precise controls vary by model and location. On many LG sets, the ACR option can be found under the additional system settings or privacy and user-agreement menus.

Users who do not need smart functions can disconnect the television from Wi-Fi and Ethernet and use a separately maintained streaming device. Merely switching the screen off should not be considered the same as physically removing power.

For televisions with integrated microphones, disabling voice features is sensible when they are not required. Where practical, users with especially sensitive conversations may choose to disconnect the set from power, although this sacrifices background updates, quick-start functionality and scheduled activity.

Network segmentation provides an additional layer of protection. Placing televisions and other smart-home equipment on a dedicated IoT or guest network can prevent them from freely contacting personal computers, network storage and work devices. The value of segmentation is containment: if one device is compromised, the attacker should not automatically inherit access to everything else in the building.

Router features such as Universal Plug and Play should be disabled unless they are needed. Owners should also avoid manually forwarding ports to a television and should check whether remote-access functions are enabled.

For organizations, televisions should be included in asset inventories, vulnerability-management programmes and network-access policies. Conference-room displays should not automatically be trusted simply because they appear to be consumer appliances.

Smart TVs Demand Computer-Level Security

The LG investigation highlights a structural problem affecting the wider connected-TV industry.

Consumers are purchasing a display, but they are also installing a continuously maintained software platform backed by advertising, analytics and cloud services. The device may contain microphones and detailed information about household entertainment while maintaining access to the same network used for work, banking and private communication.

The newly demonstrated audio surveillance appears to represent the consequences of a security compromise rather than evidence that LG routinely records every conversation. That limitation matters, but it does not remove the threat. A television capable of recording audio, storing data and communicating over the internet can become a listening device if an attacker defeats its security controls.

Until LG completes its investigation, identifies affected products and issues any necessary patches, the exact scale of the exposure will remain uncertain. The findings nevertheless reinforce a clear conclusion: smart televisions must be updated, restricted and monitored with the same seriousness applied to other network-connected computers.

© All Rights Reserved.