Back Technadu LG Smart TV Flaws Let Attackers Listen In, Even in Standby
Investigation team: Gamers Nexus, Level1Techs, and independent researchers examined several LG smart TV models, including the flagship G5.
Audio capture: Compromised TVs can record audio even when the TV appears off, storing it offline and uploading it once reconnected.
RCE flaws: Remote code execution vulnerabilities in webOS were reported to LG under responsible disclosure.
Several LG smart TV models, including the flagship OLED G5 running webOS, exhibit extensive tracking behavior and serious security weaknesses. Findings indicate that a smart TV warrants the same privacy and security scrutiny as any internet-connected computer, revealing that the TV " crawled our entire network and found dozens of unrelated devices, including smartwatches and phones of our staff who didn't even know we were working on this ."
The findings were revealed in a 135-minute video investigation published by Gamers Nexus, in collaboration with Level1Techs and independent security researchers, which combines packet captures and bench tests on retail hardware.
Network Discovery and ACR Tracking
According to Gamers Nexus, packet captures taken via Wireshark and firmware analysis showed the tested LG TVs performing extensive device and network discovery – identifying other devices on the local network, none of which have anything to do with watching television, including:
nearby Wi-Fi network names,
device-related identifiers,
Combined with Automated Content Recognition (ACR) data and advertising IDs, this network information could support detailed profiles of what people watch and the devices they use.
ACR technology samples what appears on or is heard through a TV, creates a digital fingerprint, and compares it against a reference database to identify programs, ads, and viewing habits; researchers found it operating across multiple inputs, including HDMI.
The harvested data reportedly feeds into LG Ad Solutions, the company's targeted-advertising division, which separately claims access to 363 million secondary addressable devices in the U.S. alone by tracking other hardware sharing the same network as an LG TV.
Microphone Capture in Standby and Offline Modes
Researchers demonstrated how a compromised TV could capture audio through its microphone, including when the device appeared to be off, with the microphone continuing to operate regardless of whether the screen was active.
They also showed the TV storing audio while unplugged from the internet, then retrieving and uploading it once the connection was restored.
RCE Vulnerabilities Under Responsible Disclosure
The team reported remote code execution ( RCE ) vulnerabilities in webOS network-facing services to LG. Full details, including any CVE identifiers, remain undisclosed while the responsible disclosure process continues. LG's webOS platform runs on more than 200 million televisions worldwide.
A compromised TV could provide an attacker a foothold on a or business network, access to audio, or a route to probe other devices. Owners can take a few practical steps, as Malwarebytes offers the following advice and a guide to disabling ACR :
Install firmware updates promptly, especially security updates.
Turn off ACR, viewing-information collection, personalized ads, voice recognition, and other features you don’t need under Settings, Privacy & Terms, or User Agreements.
Don’t accept every agreement by default.
Use a separate IoT or guest network for televisions, cameras, speakers, and other smart- devices.
Disable UPnP on your router unless it is genuinely needed
Avoid exposing TV services directly to the internet.
LG has not publicly commented on the investigation's findings as of this writing, and it has not announced a firmware update addressing the audio-collection behavior.
Samsung recently settled a lawsuit with the Texas Attorney General specifically over ACR data collection and monetization, and Vizio , Samsung, and Roku have each separately faced FTC scrutiny over ACR practices. In 2024, Samsung and LG's ACR raised privacy concerns.
WebOS carries prior documented remote code execution vulnerabilities – CVE-2024-1885 in LG Signage webOS and CVE-2018-17173 in LG SuperSign EZ CMS.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
