Smart TVs equipped with similar information channels—from webcams to microphones—are joining smartphones in becoming devices capable of monitoring their owners. An investigation by Gamer Nexus found that LG smart TVs record sound and actively scan local networks even when the screen is off.
Image source: LG Electronics
Author of more than two hours of stories on the channel of the same name Independent cybersecurity experts participated in the investigation and conducted profile testing on multiple LG smart TVs, including the G5 model. Analysis of network traffic and study of the firmware revealed that the TV actively scans local wireless networks and even flags those devices, including smartphones, smartwatches, computers and other devices not necessarily related to the operation of the TV.
The researchers reported that they collected internal IP and MAC addresses, single device names, signal parameters, and information about nearby Wi-Fi networks (name, signal strength, and channel). Such a dataset can be used to identify a device and determine its location. At the same time, the video’s authors noted that they were unable to decrypt all traffic and therefore could not determine the contents of each transmitted packet.
The investigation also examined the operation of ACR (automatic content recognition). The technology takes audio and video data (including screenshots or audio clips), converts it into a digital fingerprint, and matches it against a media database to determine what content is being viewed. The author claims that this telemetry also works when an external source is connected via HDMI.
This information will then be processed by LG Ad Solutions, which is responsible for targeted advertising. There are approximately 216 million LG smart TVs in use worldwide, allowing the company to collect fairly broad and representative statistics. Taking into account the non-essential devices that LG TVs scan, the company actually has access to about 363 million devices in the U.S. alone and serves ads proportional to the number of users. LG Smart TVs can also analyze the content users are watching to more accurately tailor advertising offers, which is done by selectively capturing the video and audio playing on the device.
The most serious conclusion of the investigation has nothing to do with standard ACR functionality, but rather with webOS vulnerabilities. According to the author, with their help the TV can be used to record the sound of the connected microphone even if the screen seems to be turned off. When the network connection is interrupted, the recording is saved locally, and when the connection is reconnected, the researcher can exploit the vulnerability to access it. This doesn’t prove that LG is automatically recording conversations and sending them to the company’s servers like normal, but it does prove that there is a serious vulnerability in webOS.
Some vulnerabilities, including those related to remote code execution, have gone through a responsible disclosure process, so technical details have not yet been released. The survey authors recommend disconnecting LG TVs from the Internet and using a separate device to provide online services.
If you find an error, select it with your mouse and press CTRL+ENTER.










