Skip to content
LG Smart TV Security Flaws: What Owners Need to Know

LG Smart TV Security Flaws: What Owners Need to Know

Thepcenthusiast September 8, 2026

A months-long investigation into several current LG smart TVs found the tested sets scanning networks, collecting information nearby devices, tracking viewed content and retaining voice-related data. Researchers also uncovered webOS security vulnerabilities that could give an attacker much deeper access to a compromised television, including its microphones while the screen appears off.

Gamers Nexus published the investigation after working with Level1Techs and independent security researchers. The team says it spent more than 500 hours examining retail LG OLED TVs, including the current G5, using network captures, firmware analysis and controlled security testing.

The findings raise two separate concerns for owners: what webOS collects during normal use, and what a compromised LG TV could expose if an attacker gains sufficient control.

LG TVs Were Scanning Devices on the Network

Network captures showed the tested LG TVs actively discovering other hardware on the local network. Researchers observed phones, laptops, smartwatches, printers and other connected devices being identified, including hardware unrelated to watching television.

The sets also gathered information surrounding Wi-Fi networks, including network names, signal strengths and channel information. Some local-network discovery continued when researchers switched to HDMI and used the television primarily as a display.

LG’s collection of ACR data had already attracted regulatory attention. In May 2026, Texas Attorney General Ken Paxton announced an agreement requiring LG to obtain informed consent before collecting viewing data through ACR, provide clearer disclosures and give users an opt-out.

Check other TVs : Sony Bravia A80L vs. A75L: Which 4K OLED Smart TV is Better?

Which LG TVs Are Affected?

There is currently no verified list showing that every LG smart TV suffers from every issue uncovered in the investigation.

Gamers Nexus tested several current retail LG TVs, including the OLED G5, but the researchers have not published a complete model-by-model list covering the newly disclosed security vulnerabilities.

Some findings have a much broader potential scope. ACR, advertising services and local-network discovery are webOS features rather than functions unique to one OLED model. Voice-related findings depend more heavily on hardware and configuration, including whether the TV supports built-in microphones, hands-free voice recognition or a microphone-equipped Magic Remote.

The scope of the new remote-code-execution vulnerabilities remains less clear. Researchers are withholding full exploit details while the disclosure process continues, so we do not yet know every affected webOS version or television model.

Owners should therefore avoid both extremes. We cannot say that every LG TV has every problem demonstrated in the tests, but owners of other webOS models also should not assume they are unaffected simply because their television was not shown in the investigation.

Samsung Smart TV deals : Best Samsung S95F and S90F OLED TV Deals

Can an LG TV Listen With the Screen Off?

This finding needs more context than some of the headlines surrounding the investigation suggest.

Researchers found that LG’s voice functions could keep listening for roughly 10 to 15 seconds after a voice command. Speech captured during that period could appear as plain-text transcripts in webOS logs, and the investigation showed that voice-related information could remain stored locally after the TV lost its internet connection.

The researchers also demonstrated more invasive audio access while the screen appeared off. Those tests involved televisions over which the researchers had already gained additional control.

That does not show that every LG television secretly records room conversations around the clock.

It does show what the hardware can become after a serious compromise. A smart TV may contain microphones, network interfaces and access to other connected peripherals. If an attacker gains enough control through a software vulnerability, those components can become surveillance tools rather than normal TV features.

LG previously said its TVs “do not collect, record, or store ambient conversations” and described voice recognition as an optional, user-initiated feature. The post-command listening window and retained voice transcripts give owners good reason to look more closely at how those features behave.

New webOS Security Flaws Raise the Risk

Researchers also reported new remote-code-execution vulnerabilities to LG and are withholding the technical details while responsible disclosure continues.

Remote code execution is much more serious than aggressive telemetry alone. An exploitable flaw could potentially allow an attacker to execute commands on the television and gain access to functions that normal users or applications should not control.

LG has dealt with significant webOS vulnerabilities before. In 2024, Bitdefender disclosed authentication-bypass and command-injection flaws affecting webOS 4 through 7. Researchers identified more than 91,000 internet-exposed devices running the affected service at the time. LG patched those older vulnerabilities before Bitdefender published the technical details.

A separate 2026 investigation from Spur also found residential-proxy SDKs inside a large number of LG webOS applications. Those SDKs came from third-party apps rather than LG’s television firmware itself, so they should not be confused with the new vulnerabilities. They do, however, reinforce why a smart TV deserves the same network-security attention as other connected computers in the .

Sony or Samsung TV? Sony Bravia 8 II vs Samsung S95F: Which OLED Smart TV To Get

What LG Smart TV Owners Can Do

Owners do not necessarily need to replace an otherwise good television. Limiting the TV’s network access provides the strongest privacy protection if you do not depend on webOS apps.

Disconnect the TV from the internet when webOS connectivity is unnecessary. Remove the saved Wi-Fi network and unplug Ethernet.

Use an external streaming device such as an Apple TV, Roku, Fire TV or PC. That device will have its own privacy settings, but it moves much of the smart functionality away from webOS.

Put the TV on a guest or IoT network if it must remain connected. Client isolation can prevent it from freely communicating with computers and other sensitive devices on your main LAN.

Keep webOS updated. LG may issue patches for the newly disclosed vulnerabilities as the disclosure process progresses.

Disable features you do not use , including ACR, personalized advertising, hands-free voice functions and other data-collection options available on your model.

Disconnecting the television provides a stronger barrier than relying on individual privacy toggles because it prevents the TV from sending data to external services while offline.

The Findings Are Serious, but Not Every Headline Is Accurate

The investigation does not prove that millions of LG TVs constantly record private conversations and upload them to LG. Some of the most alarming audio demonstrations involved televisions that researchers had already compromised.

What the investigation did document is still concerning. The tested LG TVs performed extensive local-network discovery, ACR could identify content shown through external inputs, voice-related information remained in system logs, and researchers found new webOS vulnerabilities capable of making a compromised television far more intrusive.

For LG owners who mainly want the panel and already use another device for streaming, the safest approach is relatively simple: keep the TV patched when necessary, limit the privacy features you do not need, and keep webOS off the network whenever possible.ated when necessary, then take webOS off the network.

Source: Gamers Nexus , Malwarebytes