LG TVs Could Record You While Appearing off if Hacked, Researchers Show
Investigation reveals potential security vulnerabilities in LG Smart TVs

Researchers say hacked LG smart TVs could be turned into covert listening devices that record audio even while the screen appears off. The claim comes from a Gamers Nexus investigation carried out with Level1Techs and independent security researchers, who tested several LG television models and examined their firmware and network behaviour.
The researchers said the recording demonstration required control of the television and did not show that LG secretly records private conversations. Their tests instead showed that microphones and other audio inputs built into or connected to LG TVs could be accessed after a device had been compromised.
Compromised Set Could Become a Listening Device
The team said it gained control of test units and demonstrated recording through built-in microphones, USB webcams, remote-control microphones and other available audio sources.
In one test involving an LG OLED G5, the television continued storing audio locally after its internet connection was removed.
According to the investigation, the audio could later be retrieved after connectivity was restored. The researchers also demonstrated that audio being played through the television could be captured from the set itself.
That distinction matters. The tests were designed to demonstrate what an attacker might be able to do after exploiting a vulnerable television, rather than to establish that such recording forms part of LG's ordinary data collection.
The investigation also reported remote-code-execution vulnerabilities to LG, but full technical details have not been published while responsible disclosure remains under way.
A compromised television could therefore carry risks beyond conventional viewing-data collection, potentially giving an attacker a foothold on a home or business network, access to audio sources or a route to probe other connected devices.
Scanning Devices Across Local Networks
The same investigation examined how LG TVs behaved on local networks. Using packet captures, firmware analysis and tools including Wireshark, the researchers said the tested televisions repeatedly identified nearby hardware.
Devices detected during testing reportedly included smartphones, PCs, smartwatches, printers, network switches, servers, 3D printers and HVAC-related equipment.
The researchers said collected information included device names, internal IP addresses, nearby Wi-Fi network names, signal strength and other device-related attributes.
Firmware analysis also indicated that nearby Wi-Fi networks could be detected, including network names, channels and signal information.
Taken together, such data could provide a detailed picture of the devices operating inside a household or workplace.
The investigation examined those findings alongside LG's automatic content recognition, or ACR, systems. ACR technology fingerprints material shown or played through a television, allowing content to be identified for functions including advertising and analytics.
Gamers Nexus said ACR remained active in some configurations even when a television was being used mainly as an HDMI display. In one test, the set repeatedly contacted LG and advertising-related endpoints, including infrastructure associated with Alphonso, the business in which LG acquired a controlling stake in 2021.
The investigation estimated that one test television was sending ACR-related data at a rate equivalent to around 4 GB per month. Activity involving LG Channels also generated network requests that, according to the investigation, could indicate which channel was being watched.
Security Questions for Connected Homes
The findings show why smart televisions need similar security consideration to other internet-connected devices. They can include microphones, apps, advertising systems and connections to the same networks used by phones, laptops, printers and smart-home equipment.
The researchers recommended disconnecting LG smart TVs from the internet while the undisclosed vulnerabilities go through responsible disclosure.
Separately, security guidance published by Malwarebytes advises users to install firmware updates promptly, disable ACR and unnecessary advertising or voice features, and consider isolating smart TVs on a guest or IoT network.
Malwarebytes also recommends disabling UPnP on a router unless it is genuinely needed and avoiding unnecessary exposure of television services to the wider internet.
The central finding remains narrower than some interpretations. The investigation did not establish that LG is secretly listening to users.
It showed that, once compromised, some tested LG TVs had the hardware and software capabilities to capture and retain audio, including while the screen appeared off. LG said on 22 July that its televisions do not collect, record or store ambient conversations and described voice recognition as an optional, user-initiated feature.
© Copyright IBTimes 2026. All rights reserved.

























