LG TV flaws could let attackers listen in, even in standby mode
Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices.
A major manufacturer in Smart TVs, LG, has come under the spotlight this week after an investigation by Gamers Nexus, carried out with Level1Techs and independent security researchers. The team examined several LG TV models, and says its found extensive device and network discovery, ACR tracking, and security weaknesses that could increase the consequences if a television were compromised.
Automated Content Recognition (ACR) technology samples what appears on or is heard through a TV, creates a digital fingerprint, and compares that fingerprint against a reference database. It can be used to identify programs, ads, and viewing habits.
Some of the researchers’ findings concern LG’s intended product behavior, while others rely on vulnerabilities that researchers say are still being disclosed responsibly. But the broader lesson is clear: A smart TV deserves the same privacy and security consideration as any other internet-connected computer.
According to Gamers Nexus, packet captures and firmware analysis showed the tested LG TVs identifying devices on the local network, such as phones, PCs, printers, switches, and smart-home hardware. The investigation also says the TVs collected nearby Wi-Fi network names, signal information, and device-related identifiers.
This network information could help build a picture of the other devices in a household. Combined with ACR data, advertising IDs, and other information, it could support detailed profiles of what people watch and the devices they use.
The researchers also demonstrated how a compromised TV could capture audio through its microphone, including when the TV appeared to be off. They even showed how the TV stored audio when it was unplugged from the internet and retrieved it after the connection was restored.
The researchers also reported remote-code-execution vulnerabilities to LG. They have not disclosed full details while the responsible disclosure process is ongoing.
A compromised television could be more than a privacy issue. It might provide an attacker with a foothold on a home or business network, access to audio, or a route to probe other devices.
How to stay safe
The concerns are not limited to one brand. Smart TVs sit at the intersection of entertainment, advertising, and the home network. Treating them as security-sensitive devices—and demanding clear, meaningful privacy choices—is increasingly part of staying safe at home.
There is no need to panic, but owners can take a few practical steps to limit what their TV collects and what it can access:
- Install firmware updates promptly, especially security updates. Check your model’s support page and the TV’s software-update settings.
- Review the privacy controls under Settings, Privacy & Terms, or User Agreements. Turn off ACR, viewing-information collection, personalized ads, voice recognition, and other features you don’t need.
- Don’t accept every agreement by default. Read each consent screen and decline optional advertising and voice-data features where possible.
- Use a separate IoT or guest network for televisions, cameras, speakers, and other smart-home devices. This limits what a compromised device can reach on your main network.
- Disable UPnP on your router unless it is genuinely needed and avoid exposing TV services directly to the internet.
Our earlier guide to disabling ACR includes instructions for several popular TV brands.
Update September 10, 2026
LG has disputed the researcher’s claims about its TVs recording ambient conversations. The company says voice data is processed only when a user holds the microphone button or when an enabled far-field voice feature recognizes a wake word such as “Hi LG.” If no wake word is detected, LG says the audio is processed locally and immediately deleted. The researchers’ audio demonstration involved a compromised TV and does not show that uncompromised LG TVs routinely record conversations.
LG confirmed that its TVs scan local networks, but said this is a standard function used for device connectivity, content sharing, and smart-home features. It also said its ACR feature is enabled only with the user’s consent. LG has not publicly addressed the reported security vulnerabilities, which are still going through responsible disclosure.
Browse like no one’s watching.
Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →