Researchers found LG TVs scanning local networks and identifying phones, smartwatches, printers, and other nearby devices.
The investigation says LG TVs can log voice commands as text and upload stored data after reconnecting online.
LG Ad Solutions says its ad business reaches 216 million LG smart TVs worldwide.
Researchers recommend disconnecting LG smart TVs from the internet and using an external streaming device instead.
Key Takeaways by nexos.ai , reviewed by Cybernews staff.
LG smart TVs can listen in on voice commands, gather data that reveals your location, and scan your for other connected devices, according to a major new investigation into the company's webOS platform.
Researchers working with independent technology outlet Gamers Nexus captured LG televisions scanning local networks and identifying phones, smartwatches, printers, air conditioning units, and many other devices that had never been connected to the TV.
The investigation also found that the TV sets use an advertising technology called Automatic Content Recognition (ACR) to identify what was being watched across different inputs, while voice interactions could be converted into plain text and stored in logs on the television.
In one test, researchers said voice data continued to be stored after the TV was disconnected from the internet, before being uploaded once the connection was restored.
The findings are significant given the size of LGs smart TV business.
LG Ad Solutions says its global footprint encompasses 216 million LG smart TVs, and its advertising operation uses ACR viewing data to help its advertisers understand audiences.
Smart TVs and displays like this can also be found in hotel rooms, hospitals and boardrooms, potentially placing them alongside sensitive conversations and devices.
What the investigation revealed
Gamers Nexus worked with cybersecurity researchers MrBruh and unturn, alongside Wendell Wilson of Level1Techs, to investigate retail LG TVs and the company’s webOS software. The results are presented in a 135-minute video published on YouTube .
Using the network analysis tool Wireshark, which allows researchers to inspect traffic traveling to and from devices, the team found the televisions conducting sweeps of their local networks.
In one test, an LG TV identified 38 other devices, including smartphones belonging to staff who were unaware of the investigation, smartwatches, a 3D printer, an air purifier, thermostats, and a dev board.
According to Gamers Nexus, testing showed LG TVs were capable of collecting and identifying:
IP addresses and geolocation data
Internal IP addresses belong to other devices on the network
Names, signal strengths, and channels of neighboring WiFi networks
Phones, smartwatches, and other connected hardware
Content displayed on the TV using ACR
Audio fingerprints of content played through the television
Voice commands converted into plain text and stored in on-device logs
Privacy and consent settings stored by the TV (and whether users had opted in or out)
Information surrounding WiFi networks can potentially be used to help determine a device's physical location, Wilson noted.
Gamers Nexus said much of the network discovery and data collection it observed was built into LG’s TVs rather than the result of a security vulnerability.
The investigation also reported that its test television was sending around 4GB of ACR-related data back to LG each month.
LG Ad Solutions, which is spun out as a separate entity from the smart TV business, openly promotes these viewing insights to advertisers, with marketing material saying ACR can identify TV shows, movies, ads, gaming, and other viewing behavior.
In the US, the company advertises access to 49 million LG smart TVs and 363 million “addressable secondary devices.”
TV microphones raise concerns
Responding to a recent lawsuit in Texas aimed at five TV companies accused of using ACR technology to “spy” on viewers, LG has said publicly that its TVs “do not collect, record, or store ambient conversations.”
However, Gamers Nexus’s findings relate specifically to voice commands rather than background conversations.
The researchers found that speech captured during voice interactions could be converted into plain text and stored in logs on the television.
Researchers said the microphone remained active for 10 to 15 seconds after someone stopped speaking, potentially capturing bystanders.
They also captured microphone audio while the television appeared to be switched off, in standby mode.
Have thoughts this topic? Others do, too. Join them in the discussion.
Researchers separately uncovered remote code execution vulnerabilities in webOS, which they said could potentially turn an affected TV into a covert listening device.
However, details are being withheld while the flaws go through a responsible disclosure process.
Gamers Nexus does not claim LG is deliberately using its TVs as always on listening devices, but its researchers recommended disconnecting LG smart TVs from the internet and using an external streaming device instead.
A TV tracker via LG channels
Researchers also identified a Conviva video analytics tracker in the TV feed, adding another layer of monitoring around how content is consumed.
Researcher Mr. Bruh said IPTV viewing could be exposed through network traffic.
There’s no privacy watching IPTV via LG channels, independent cybersecurity researcher, Mr Bruh, said.
He explained that this was because DNS requests can potentially be used to determine which channel is being watched at a given time. That information, he added, could potentially be visible to others on the local network as well as an internet service provider.
smart TV privacy concerns
The investigation follows separate research into apps distributed through smart TV stores.
Threat intelligence company Spur examined more than 6,000 apps available through LG and Samsung TV stores and found 2,058 contained residential proxy software , which can allow third parties to route internet traffic through a user's connection.
Following the disclosure, LG told security journalist Brian Krebs that residential proxy networks were “not an intended use for LG smart TVs” and said apps that failed to remove the functionality would be suspended.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
