LG smart TV privacy investigation reveals unauthorized audio and network scanning
A security investigation by Gamers Nexus and Level1Techs revealed that LG smart TVs capture microphone audio in standby mode and perform unauthorized local network scanning. The findings raise significant concerns regarding the privacy implications of Automatic Content Recognition (ACR) technology and potential remote code execution vulnerabilities within the webOS platform.
Key Takeaways
- Microphone audio is captured and stored locally even when the screen appears powered down in standby mode
- Automatic Content Recognition (ACR) technology samples HDMI and streaming data to track 216 million global TVs
- LG Ad Solutions monitors 363 million addressable secondary devices connected to the same household networks
- Security researchers identified remote code execution vulnerabilities within the webOS platform during testing
Why It Matters
The discovery of active network scanning and audio logging while devices are in standby highlights a significant shift in how hardware manufacturers monetize user environments beyond simple viewing data. For the streaming ecosystem, this level of data harvesting provides LG Ad Solutions with granular cross-device mapping that traditional streaming apps cannot easily replicate. However, the revelation of remote code execution flaws in webOS suggests that these extensive data collection features may also serve as unmonitored entry points for network-wide security breaches. Watch for whether LG issues a formal firmware patch to address the specific standby audio logging and network discovery behaviors identified in the LG TV data collection investigation.
Additional Context
LG's webOS platform has become a central pillar of the company's advertising and content strategy, powering its free ad-supported streaming service LG Channels and its LG Ad Solutions division. The platform's reach expanded significantly in 2025 when LG announced that webOS would be licensed to more than 400 TV brands worldwide, a move that broadened the potential surface area for any data collection practices embedded in the operating system. That licensing expansion means the behaviors identified in the Gamers Nexus and Level1Techs investigation could affect not just LG-branded sets but third-party televisions running the same software stack.
The privacy concerns around smart TV data collection are not new, but regulatory attention has intensified. In 2024, the FTC settled with Vizio over allegations that the company's ACR technology captured viewing data from millions of smart TVs without adequate consumer consent, resulting in a $3 million penalty. LG's situation differs because the investigation revealed audio capture and network scanning rather than purely viewing-history collection, which may trigger different regulatory frameworks. The European Union's General Data Protection Regulation and the California Consumer Privacy Act both impose strict requirements on passive data collection from always-connected devices, and Verizon disclosed that its 60,000-site vRAN is now applying agentic AI to planned configuration changes while publicly calling for industry-wide interoperability standards for automated systems, a parallel debate about how connected infrastructure should handle autonomous data gathering without explicit user direction.
On the technical side, the remote code execution vulnerabilities found in webOS echo a pattern seen across smart TV platforms. In 2023, researchers disclosed critical flaws in Samsung's Tizen OS that allowed attackers to install malicious applications remotely. LG's webOS has faced similar scrutiny before; in 2021, a security researcher demonstrated a chain of exploits that could achieve root access on LG televisions through the TV's web browser. The current findings add a new dimension because the network scanning behavior means a compromised LG television could serve as a pivot point into a home network, exposing phones, laptops, and IoT devices that users assume are isolated from their entertainment hardware. Nokia has recently pushed its own automation agenda with an Autonomous Networks Agent Library for IP networks, illustrating how even telecom vendors are grappling with the governance challenges of autonomous systems that collect and act on network data without continuous human oversight.
Read full article at allaboutcookies.org
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source