LG smart TVs caught logging audio with screen off and snooping on local devices

Recent investigations by Gamers Nexus have uncovered significant privacy concerns regarding LG smart TVs, specifically regarding audio logging and local network snooping. Tests revealed that LG TVs, even with the screen off or in standby mode, actively capture microphone audio and log user voice prompts in plain text. This data is then uploaded to LG Ad Solutions once the TV reconnects to the internet. Furthermore, the TVs continuously scan home networks to map connected devices, gathering information such as IP addresses, Wi-Fi network names, and location data, all of which is used to fuel LG's targeted advertising efforts. The scope of data collection extends beyond Automated Content Recognition (ACR) and includes potentially sensitive audio information, raising serious privacy implications for millions of LG smart TV owners globally. Researchers recommend disconnecting LG TVs from the internet and using external streaming devices as a precautionary measure.

AI Signal Decode

LG smart TVs have been found to actively scan local networks for other devices, including phones and smartwatches, collecting IP addresses, Wi-Fi network names, and location data. This information is fed into LG Ad Solutions, the company's advertising division, which claims access to data from 363 million addressable devices in the US alone. This extensive network mapping capability, combined with the potential for audio logging, presents a significant privacy risk, as it allows LG to build a detailed profile of user activity and connected hardware within a household.

Beyond network scanning, new testing has revealed that LG smart TVs can capture microphone audio even when the screen is off or in standby mode. Voice prompts and audio inputs are logged and, in some cases, stored locally before being uploaded to LG servers when internet connectivity is restored. This capability raises concerns about continuous surveillance, as audio data can be collected without explicit user awareness or interaction, going beyond the previously understood functionality of Automated Content Recognition (ACR).

The findings also include evidence of remote code execution vulnerabilities within the webOS operating system, which are currently undergoing responsible disclosure. Given the broad network listeners and data sweep functionalities enabled by default, security researchers strongly advise users to disconnect LG smart TVs from the internet. Their recommendation is to rely on external streaming devices to mitigate these privacy and security risks, highlighting a potential erosion of trust in smart TV manufacturers' data handling practices.