Cybersecurity

LG’s smart TVs log your voice in standby mode — and scan every device in your home

Susan Hill

The screen is dark. The remote is down. The microphone is still on. Researchers from Gamers Nexus, working alongside network security specialists at Level1Techs, have documented that LG smart televisions running webOS capture clean audio through their built-in microphones while the display is in standby mode — a state most owners associate with the device being effectively off. In tests conducted on retail LG OLED hardware, including the current G5 model, the microphone continued operating regardless of whether the screen was active.

The recordings do not disappear when the TV loses its internet connection. When the research team disconnected a test unit from its Ethernet cable and generated audio near the microphone, the television stored the voice input locally. The moment network access was restored, it transmitted the stored files to external servers. That behavior suggests the data collection is not a live-streaming process but a persistent logging system designed to capture audio independently of a network connection.

Audio was only one dimension of the investigation’s findings. Wireshark packet captures — a standard network analysis technique that logs all traffic entering and leaving a device — showed the televisions continuously scanning the local home network. Those scans collected internal IP addresses of nearby phones, tablets, and smartwatches, alongside the names and signal strengths of neighboring Wi-Fi networks and the location data those signals imply. The surveillance extends beyond the television itself to every device sharing the same router.

Some of the network scan data flows into LG Ad Solutions, the company’s advertising division. LG Ad Solutions claims access to 363 million “secondary addressable devices” in the United States — hardware that does not belong to LG but shares a network with an LG television. That figure illuminates the scale of the operation: the TV is functioning not just as a display but as a gateway for building advertising profiles across the entire household.

LG had not responded to the investigation’s findings by publication time. The company’s webOS setup flow requires users to accept a terms-of-service agreement that includes data-sharing language, which may be cited as legal grounds for the data collection. Whether the offline audio storage and upload mechanism constitutes lawful processing under the EU’s General Data Protection Regulation — applicable wherever LG sells televisions in Europe — has not been adjudicated for this specific configuration. Researchers also documented remote code execution vulnerabilities in webOS currently undergoing responsible disclosure, meaning a separate attack surface exists that external actors could potentially exploit.

LG is not the first smart TV manufacturer to face privacy scrutiny. Samsung, Vizio, and Roku have each faced Federal Trade Commission attention over Automated Content Recognition — the technology that fingerprints content on any HDMI input to log viewing behavior. What distinguishes the LG findings is the microphone behavior in standby and the active local network scan, which go beyond content fingerprinting into ambient monitoring of the home. The Gamers Nexus team’s recommendation to its viewers was direct: disconnect the television from the internet and use an external streaming device instead.

The webOS vulnerabilities identified during the investigation are currently in responsible disclosure, which typically culminates in a coordinated public disclosure date after a patch is prepared. LG’s webOS platform runs on more than 200 million televisions globally. No firmware update addressing the audio collection behavior has been announced, and LG Ad Solutions has not confirmed whether it will modify its secondary device data practices following the investigation’s publication.

Tags: , , , , ,

Discussion

There are 0 comments.