
LG says its smart TVs are not spying on you. A two-hour Gamers Nexus investigation, backed by Wireshark packet captures and firmware logs, tells a different story. Published September 6, the deep-dive documented LG OLED televisions — including the flagship G5 — actively scanning home networks, recording ambient audio in standby mode, and doing something that no standard smart home device does: buffering audio locally when the internet connection drops, then quietly uploading it when connectivity returns. LG’s official position, issued September 9: the spying claims are “not true.” What LG did not deny: the network scanning.
The Detail That Doesn’t Have an Innocent Explanation
Most of the individual behaviors documented in the investigation have been waved away as normal smart home functionality. Network scanning? UPnP discovery. ACR data collection? You agreed to it during setup. Voice recognition logging? Needed for the AI assistant. These explanations are debatable, but they exist.
The offline audio buffering does not have a clean explanation. Researchers placed an LG G5 in standby, disconnected its Ethernet cable, and then spoke near the microphone. The TV continued recording. When connectivity was restored, the buffered audio was transmitted. The microphone remained active for 10 to 15 seconds after speech ended — in standby, with the screen off, with no internet access. Malwarebytes confirmed LG says audio capture only happens when a wake word is detected or the voice button is held. The on-device logs the researchers extracted contradict that claim directly.
What LG Actually Admitted
LG confirmed that its televisions scan local networks for other devices, calling it “a standard function of smart TVs and smart home devices” that enables connectivity and content sharing. In testing, a single LG TV catalogued 38 devices on a home network — including smartphones, PCs, printers, smartwatches, routers, thermostats, and server baseboard management controllers. LG also confirmed the existence of ACR (Automatic Content Recognition), branded internally as Live Plus. The company says it requires explicit opt-in consent. Reporting from Tom’s Hardware noted that disabling it requires navigating five separate menu levels — a design choice that raises obvious questions about how earnest that opt-in process really is.
The Part Most Coverage Missed: Your Work Setup Is In Scope
ACR does not distinguish between Netflix and your HDMI-connected work monitor. The Live Plus system fingerprints audio across all inputs — streaming apps, cable boxes, gaming consoles, and any device connected over HDMI. If you use a TV as a secondary monitor, or have one in a home office within earshot of a video call, that content is being sampled and sent to Alphonso Inc., LG’s third-party analytics partner. Combine this with the LAN enumeration that LG openly confirmed — your TV now has a partial inventory of your home office infrastructure — and the threat model starts looking less like a consumer privacy concern and more like a lateral movement opportunity.
There Are Also Unpatched RCE Vulnerabilities
The same research team separately reported remote code execution vulnerabilities in webOS’s network-facing services to LG. Full details and CVE numbers remain undisclosed while responsible disclosure runs its course, but the researchers demonstrated a proof-of-concept: an LG G5 converted into a remote listening device, screen appearing off, operating under external control. webOS has a documented history of RCE issues — CVE-2023-6319, CVE-2023-6318, and CVE-2024-1885 in LG Signage are precedent. A TV that scans your network and has unpatched RCE vulnerabilities is not just a privacy problem — it is a network security problem.
Why This Keeps Happening
The business model makes the behavior rational. LG sells aggregate viewing data to advertisers and content studios. TV hardware runs on thin or negative margins; the surveillance data is where the actual revenue comes from. This is not unique to LG — Samsung, Sony, Vizio, and TCL operate similar systems. Vizio settled an FTC lawsuit over it in 2017 and kept going. The Texas Attorney General sued all five manufacturers in December 2024 for ACR privacy violations. The pattern suggests that the legal and reputational cost of this data collection has, so far, been lower than the revenue it generates.
Five Things to Do Right Now
- Disable Live Plus (ACR): Settings → All Settings → General → System → Additional Settings → LivePlus → Off
- Revoke viewing data consent: Settings → Support → Privacy & Terms → User Agreements → uncheck Viewing Information
- Disable Far-Field Voice Recognition: Settings → General → AI Service → Voice Recognition → Off
- Network isolation: Move the TV to a guest VLAN, separate from your development machines and home servers. This is the most effective mitigation available today.
- Apply firmware updates: When LG publishes patches for the disclosed RCE vulnerabilities, apply them immediately. Check Pocket-lint’s ACR guide for step-by-step disabling instructions.
The “opt-in” framing only works if users know the option exists. Most don’t, and LG’s menu design makes it easy to stay that way. The packet captures, on the other hand, do not care about UX choices.













