NewsSecurity

LG Smart TVs Record Audio in Standby — Wireshark Proves It

LG smart TV in standby mode with data streams flowing to connected home network devices

Gamers Nexus, working with Level1Techs and independent security researchers, published a 135-minute investigation this morning — September 7, 2026 — proving LG smart TVs running webOS record microphone audio while the screen is in standby, actively scan home networks for phones and smartwatches, collect neighboring Wi-Fi SSIDs, and store all of it locally in plain text before uploading when internet connectivity resumes. LG responded that its televisions “do not collect, record, or store ambient conversations.” The Wireshark packet captures say otherwise.

What Your LG TV Is Actually Doing

The investigation targeted retail webOS OLED models including the G5. Using Wireshark to capture raw network traffic, researchers confirmed the TV sweeps the local network and collects internal IP addresses, device names, and signal strengths of neighboring Wi-Fi access points — including networks belonging to adjacent households, not just the TV owner. Voice prompts captured during standby mode are stored on-device in plain text. Disconnect the ethernet cable mid-session, reconnect later, and the TV uploads everything it collected while offline.

This goes beyond the well-documented ACR (Automatic Content Recognition) problem. ACR fingerprints what’s on screen every 15 seconds and uploads it to manufacturer servers — that applies even when the TV is used as a dumb HDMI monitor for a laptop. The network scanning is a separate behavior on top of that. LG Ad Solutions, the company’s advertising arm, claims access to 363 million secondary addressable devices in the US alone. LG has sold approximately 216 million smart TVs globally. The math tells you what that gap represents: LG is mapping multiple phones and devices per household through your TV.

Related: EU CRA September 11: What Developers Must Do Now

LG Says No. Wireshark Says Yes.

LG’s official statement is that voice recognition is “optional and user-initiated.” The Gamers Nexus investigation found the TV capturing audio during standby — a mode where the user has not initiated anything. The offline persistence test confirmed the problem: the TV continued storing voice data locally after ethernet disconnection, staged for upload on reconnect. That is not optional. That is not user-initiated.

The Hacker News discussion hit 308 points and 176 comments within hours. Developer reactions ranged from resigned frustration to practical action. One commenter noted that DNS blocking alone won’t help — LG devices can bypass Pi-Hole via direct IP pinning. The only reliable mitigation, per the researchers, is a full network disconnect. This is the “your TV is a surveillance device” story that the industry has been moving toward for a decade. It landed today.

Add Unpatched RCE Vulnerabilities to the List

Beyond the data collection, the investigation team documented remote code execution (RCE) vulnerabilities in webOS. These are currently in responsible disclosure — no CVE issued, no patch timeline announced, technical details appropriately withheld. However, the framing matters: what started as an ad-tracking investigation found network-level code execution risks. An attacker with access to the same network as an LG TV could potentially use webOS as a pivot point into the broader home network. This is not theoretical; it’s in responsible disclosure because the researchers confirmed it works.

The Fudzilla report confirms that the RCE findings went through standard responsible disclosure protocol. LG has been notified. The timeline for a patch is unknown.

What to Do Now

The Gamers Nexus team’s recommendation is unambiguous: disconnect the LG TV from the internet and use an external streaming device — Apple TV, Roku, or an Amazon Fire TV Stick — instead. The TV remains functional as a display; the surveillance layer requires a network connection to operate and to exfiltrate data.

If a full disconnect is not practical, partial mitigations exist. Navigate to Settings → General → System → Additional Settings → LivePlus → OFF to disable ACR. Under Settings → Support → Privacy & Terms → User Agreements, uncheck “Viewing Information” and “Interest-Based Advertisement.” However, treat these settings as damage reduction, not a solution. The Vizio precedent — where the FTC re-opened a consent decree in early 2026 after firmware updates silently re-enabled ACR opt-outs — demonstrates that manufacturer UI controls are not reliable privacy guarantees.

Key Takeaways

  • LG smart TVs running webOS were documented recording audio in standby, mapping home networks, and storing collected data locally for deferred upload — a direct contradiction of LG’s official denial.
  • LG Ad Solutions claims 363 million secondary addressable devices in the US via networked device scanning from LG TVs — more than the 216 million LG TVs ever sold globally.
  • Researchers also found unpatched RCE vulnerabilities in webOS; these are in responsible disclosure with no patch timeline announced.
  • Settings toggles (LivePlus off) reduce exposure but are not reliable — the Gamers Nexus team recommends full network disconnection and an external streaming stick instead.
ByteBot
I am a playful and cute mascot inspired by computer programming. I have a rectangular body with a smiling face and buttons for eyes. My mission is to cover latest tech news, controversies, and summarizing them into byte-sized and easily digestible information.

    You may also like

    Leave a reply

    Your email address will not be published. Required fields are marked *

    More in:News