LG smart TVs pose serious privacy and security risks. LAN devices can be spied on and ambient sounds can be recorded.

📅 2026-09-08

Abstract:

The well-known technology hardware media Gamers Nexus, together with Level1Techs and a number of independent network security researchers, recently released an in-depth joint investigation report that took several months to complete. Test results show that LG smart TVs equipped with webOS system have multiple radical data collection and privacy security risks, such as high-frequency scanning of home LAN devices, collecting fingerprints of surrounding Wi-Fi networks, and recording microphone audio when the screen is turned off, during daily use or even in standby mode.

In tests on a variety of retail OLED smart TVs on the market, including LG G5, the research team used packet capture tools such as Wireshark to monitor network traffic and found that after the TV was connected to the home network, it would actively and continuously broadcast detections to the local area network (LAN) to identify and list other networked hardware unrelated to the basic playback functions of the TV, including smartphones, smart watches, personal computers, thermostats, printers, and internal servers. In addition to sniffing internal IP addresses and LAN topology, the system also collects the name (SSID), signal strength, and rough geographical location information of nearby Wi-Fi networks. Relevant data is confirmed to be transmitted back to LG Ad Solutions, LG’s precision advertising business unit, to profile family users and support cross-device targeted advertising.

What raises more privacy concerns is the benchmark test of the TV’s built-in microphone. Researchers found that after a specific interaction or triggered wake-up, even if the TV screen has dimmed and entered a standby mode that appears to be completely turned off, the device can still continue to record clear ambient speech in the background and temporarily store the speech recording in the local storage medium. In the offline test where the TV's Ethernet and wireless network connections were deliberately cut off, the recording data was not lost, but was encrypted and packaged and uploaded to the remote server as soon as the network was reconnected.

In addition, the investigation team also discovered multiple undisclosed Remote Code Execution (RCE) vulnerabilities in webOS and demonstrated how attackers can obtain the highest Root privileges of a device with minimal user interaction or the need for complex credentials, thereby completely turning the TV in the living room into a springboard for eavesdropping and lateral intranet penetration that can be remotely controlled. Tests also show that even if some models are equipped with a physical microphone disconnect switch, the external USB accessory audio channel may still bypass the switch at the hardware level to maintain sound reception.

Faced with the pervasive automatic content recognition (ACR) and telemetry data return mechanisms of such smart home appliances, network security experts recommend that users who are highly sensitive to privacy should carefully evaluate the network permissions of smart TVs. The most thorough prevention method is to completely disconnect the smart TV from Wi-Fi and network cables, use it only as a pure display panel, and use independent streaming media set-top boxes with stricter permission controls such as Apple TV to carry playback needs; if the Internet must be connected, it is recommended to isolate the TV in an independent guest Wi-Fi or IoT virtual local area network (VLAN), and manually turn off all personalized advertising and automatic content tracking switches in the system settings.

This video records in detail the security research team’s actual testing process and technical evidence collection details of LG TV packet capture analysis, standby recording and LAN scanning.

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet