Article is online

Investigation Finds LG Smart TVs Continue Recording and Scanning Networks Even When 'Off'

Investigation Finds LG Smart TVs Continue Recording and Scanning Networks Even When 'Off'

Highlights

After a month-long, costly forensic investigation, Gamers Nexus discovered that certain LG smart TV models keep recording audio and scanning home networks even when the screen appears off or the Ethernet is unplugged. Recorded audio and transcripts were retained locally and could be exfiltrated later, and the sets probed and cataloged dozens of devices on the local network. The team also found multiple webOS vulnerabilities that could enable remote takeover and evidence that some tracking and ACR (automatic content recognition) traffic occurs irrespective of user consent.

Sentiment Analysis

  • The overall sentiment of this report is mixed-to-negative. It combines credible, technical findings with alarming privacy implications and security flaws. The tone is investigative and critical, emphasizing risks to user privacy and device security while documenting methodical testing and measured conclusions. The practical recommendations are cautious and defensive: disconnect or fully power-cycle devices, treat on-screen privacy indicators as unreliable, and consider using the TV only as a display or using external set-top hardware. Technical details and demonstrations lend weight to the claims, but some specifics remain under responsible disclosure and vendor response is pending.

75%

Article Text

Gamers Nexus (often called GN) published a detailed video report after investing over a month, roughly $70,000 in cost, and more than 500 hours of analysis into LG smart television models such as the LG G5 and G3. The investigation sought to determine what the devices record and transmit during normal operation and under laboratory conditions. The researchers enlisted three security analysts and performed both software and hardware inspection. Their results indicate that turning the screen off or unplugging network cables does not guarantee the TV stops listening or monitoring the home network.

In their tests, microphones and connected webcams continued to record clearly even when the display was turned off. Audio captured while the TV was disconnected from the network remained stored on the device and was later transmitted when network connectivity was restored. The team also demonstrated that voice input was being converted into plaintext transcripts and written to logs. The investigators intentionally spoke fictional personal data — false birthdates and social security numbers — and were later able to recover those exact strings from saved logs. On newer models, debug-level logs were written to RAM or disk areas that did not get cleared by powering the display down; only a full power disconnect reliably removed the stored material.

The report describes how wake-word activation leaves the set listening for longer periods — approximately 10 to 15 seconds after detecting audio — and the microphones proved effective at unusually long distances: clear audio capture extended toward 70 feet in some tests, with perfect recognition within roughly 40 feet. Disabling the microphone through on-screen menus was not a reliable protection. The researchers showed that inputs over HDMI, Bluetooth, USB-connected speakers or webcams, and even microphones built into some remote controls could capture sound. They also demonstrated remote techniques that could re-enable voice recognition that appeared to be turned off in the UI, indicating the on-screen state cannot be fully trusted.

Beyond audio concerns, the team documented extensive network reconnaissance. The TVs periodically scanned the local network and identified dozens of neighboring devices — in one case enumerating at least 38 devices, including smartwatches and phones belonging to people in the household. Packet captures quantified the traffic: a device used only as an external monitor still connected to multiple endpoints and exchanged megabytes of data per hour, while a unit with full feature consent reached far higher connection counts and data volumes. Significant portions of this traffic were directed at third-party ACR services such as Alphonso, and some connections occurred even when users explicitly declined terms. The researchers noted that device identifiers were treated in a way that allows persistent tracking across reboots and that some transmissions were sent unencrypted, making interception trivial on a local network.

GN also found multiple security vulnerabilities in the TV operating system (webOS), including remote code execution vectors. One demonstrated attack involved a forged pairing popup in the built-in browser which, if clicked, permitted full device takeover. Another zero-day, described as highly serious, could reportedly be triggered remotely without user interaction; details remain withheld while disclosure procedures proceed. The combined effect of persistent recording, network scanning, third-party ACR callbacks, and exploitable software flaws creates a privacy and security profile the researchers labeled invasive and unacceptable.

LG has previously stated that its TVs do not collect, record, or store ambient conversations and that voice recognition is an opt-in feature. GN counters that this wording is misleading: practical tests show listening persists beyond what a user would expect from a brief wake-word activation, and that saved data and network behavior contradict the notion that ambient audio is not retained. At the time of the report, LG had not provided a substantive public response addressing the specific technical findings.

The investigators offered straightforward advice: treat vulnerable smart TVs as untrusted networked devices. Where possible, use the television as a passive display by fully cutting network access and power, consider using an external streaming device or set-top box for smart functionality, and verify privacy settings such as "Do not sell my personal information" are actually enforced. The most dependable way to prevent on-device retention of audio is a complete power disconnection; menu-based data wipes may only notify servers rather than effectively clear local logs. GN concluded that, given the scale of collection and the availability of remote exploits, they could not recommend LG smart TVs to privacy-conscious consumers.

Beyond the technical concerns, the report places the findings in a broader commercial context: many TV manufacturers are investing heavily in advertising platforms and data-driven services because advertising margins are far higher than hardware margins. This business incentive helps explain persistent ACR marketing efforts and device-level tracking even when hardware is sold at low margins. The controversy underscores a growing tension between convenience features and the tradeoffs they demand in privacy and security.

Key Insights Table

AspectDescription
Persistent RecordingMicrophones and connected webcams continued recording even when the screen was off; audio stored locally and later transmitted.
Network ScanningTVs scanned the home network and discovered dozens of devices, sending data to third-party services.
Data HandlingTranscripts saved in plaintext; some identifiers allow persistent tracking and some communications were unencrypted.
VulnerabilitiesMultiple webOS flaws found, including remote code execution and at least one severe zero-day.
MitigationRecommendations: fully disconnect power to clear audio logs, disable network use, or use an external device instead of the TV's smart features.
Last edited at:2026/9/10

Power Trader

ZNews Columnist