Article is online

LG Smart TVs May Be Listening and Mapping Your Home Even When Seemingly Off

LG Smart TVs May Be Listening and Mapping Your Home Even When Seemingly Off

Highlights


Investigators discovered LG smart TVs scanning an entire home Wi‑Fi network and capturing microphone audio even when screens appeared dark or the set was disconnected. Many of the behaviors center on Automatic Content Recognition (ACR) that fingerprints on‑screen or audio content. Researchers also found remote‑access vulnerabilities and hidden residential‑proxy code inside apps. Notably, a muted microphone and an unplugged network connection did not prevent audio capture or later upload. LG had recently reached a settlement over viewing‑data collection, but the new tests raise fresh privacy and security questions.


Sentiment Analysis



  • This piece carries a predominantly negative sentiment toward current LG smart TV practices. The investigation highlights multiple privacy and security shortcomings: ongoing data collection, hidden microphones, persistence of ACR during HDMI use, and unpatched remote‑execution bugs. Users’ trust is undermined by evidence that mute settings and network disconnection do not reliably stop data capture. Corporate behavior — including ad executives' statements about owning on‑screen data and a late addition of forced arbitration to user terms — reinforces a critical view. The tone is cautionary and alarmed, emphasizing risk to consumer privacy and potential misuse by bad actors.



  • 80%




Article Text


Recent investigative work by a digital media outlet and hardware reviewers, supported by independent security researchers, found that several LG smart television models perform extensive network and audio monitoring in ways consumers might not expect. The team spent hundreds of hours and significant resources to analyze device behavior, revealing that LG sets can scan a household's entire Wi‑Fi network using automatic discovery protocols, mapping phones, laptops and smart devices connected to the same router. These scans occur even when the TV is being used only as an external monitor via HDMI, which does not appear to disable the monitoring functionality.



The core of the activity centers on Automatic Content Recognition (ACR), software that creates a digital fingerprint of on‑screen images or audio and checks that fingerprint against a reference database to identify content. According to the report, LG’s ACR continues to operate across input sources and remains active under conditions where a user would reasonably assume monitoring had stopped. In controlled tests, researchers extracted clear microphone audio from a TV with a dark screen and repeated the test after disconnecting the TV from the internet; the device stored audio locally and later uploaded recordings once it regained connectivity. A mute setting applied to the TV’s main microphone did not prevent retrieval of recordings from a secondary, hidden microphone.



Beyond audio capture and ACR, the investigation uncovered software vulnerabilities that raise additional security concerns. Remote‑code‑execution flaws were found that, if exploited, could allow an attacker to run commands on a TV remotely. One described scenario uses the TV’s internal browser to accept a malicious pairing prompt that effectively grants remote access without physical interaction. Disclosure of technical details is ongoing, but researchers warned that some issues remain unpatched.



Security researchers also reported instances of residential‑proxy code embedded within apps on LG's webOS store. This code can relay other users’ internet traffic through a buyer’s home connection, making that traffic appear to originate from the homeowner’s IP address. According to reporting, a substantial portion of apps examined contained such code; the company said it is working with developers to remove or suspend offending apps. The presence of this functionality adds a layer of risk beyond passive monitoring: a compromised or intentionally malicious app could enable covert rerouting of network traffic through the device.



These findings arrive in the context of regulatory and legal scrutiny. LG reached a settlement with Texas authorities requiring informed consent before collecting ACR viewing data, and an opt‑out mechanism. However, investigators found that certain privacy toggles remained off by default prior to internet connection, undermining the practical effect of such measures. The company also recently amended its lengthy user terms to add forced arbitration language, preventing consumers from joining class actions — a move critics pointed to as poorly timed following the publication of the initial report.



The broader implications concern consumer expectations, transparency and accountability. Statements from advertising executives shown in the investigation — including candid remarks about the value of owning access to the TV screen for ad targeting — illustrate how data flows can be monetized. The report names third‑party partners involved in ACR processing and traces how viewing and device data could be linked across household devices for advertising purposes.



From a practical standpoint, users who wish to avoid potential monitoring face limited, imperfect options: reviewing and changing privacy settings (where available), disconnecting devices from the network when not in use, or using non‑smart displays. However, the investigation shows that simple steps like muting the visible microphone or unplugging ethernet may not fully prevent data collection or later transmission. The findings underscore the importance of clearer consumer disclosures, robust security patching, and stronger regulatory safeguards to align device behavior with reasonable user expectations.



Key Insights Table



































Aspect Description
Network Scanning TVs use UPnP and other protocols to map devices on the home Wi‑Fi network, even when used as an HDMI monitor.
Audio Capture Microphone audio was recorded while the screen appeared off; recordings can be stored and uploaded after reconnection.
Automatic Content Recognition (ACR) ACR fingerprints audio/video to identify content; it may remain active across inputs and without explicit consent.
Security Vulnerabilities Remote‑code‑execution flaws were found, enabling potential remote control; some issues remain under disclosure.
Residential‑Proxy Code Some apps contained code to route other users’ traffic through the homeowner’s connection, posing privacy and legal concerns.
Regulatory and Legal Context LG settled with Texas over viewing‑data practices; critics note default settings and added forced arbitration in updated terms.

Last edited at:2026/9/7

Power Trader

ZNews Columnist