Your LG TV May Be Watching the Network Even When the Screen Is Off
- The Mess: Security researchers found LG smart TVs scanning local networks, collecting extensive viewing data and, on compromised test devices, capturing microphone audio while the screen appeared to be off.
- The Damage: A compromised TV could become a surveillance device sitting inside the same network as your phones, PCs, printers and smart-home hardware.
- The Fix: Update the TV, disable unnecessary ACR and voice features, and put the television on an isolated IoT network.
Your television has a microphone.
It has Wi-Fi.
It runs an operating system.
It installs applications.
And it sits inside your home network.
That makes a Smart TV a computer with a very large screen.
A new investigation by Gamers Nexus, Level1Techs and independent security researchers examined several LG televisions and found extensive network discovery, content tracking and security weaknesses in webOS.
The most uncomfortable finding came when researchers looked at what happened while the television appeared to be switched off.
The TV Was Still Doing Things
The investigation found LG TVs identifying devices on the local network, including computers, phones, printers and other connected equipment.
The televisions also detected nearby Wi-Fi networks and collected information such as network names and signal characteristics.
That creates a surprisingly detailed picture of a household.
The TV knows that a phone exists.
It knows that a laptop exists.
It knows which networks are nearby.
Combine that with advertising identifiers and viewing information and the television becomes a useful sensor for the environment around it.
LG says network discovery is a normal function required for smart-TV features.
The company also disputes the broader claim that its TVs routinely record ambient conversations.
Then Researchers Tested the Microphone
This is where the story gets much more interesting.
Researchers demonstrated that a compromised LG TV could capture microphone audio while the screen appeared to be switched off or in standby.
They also demonstrated that audio could remain stored locally while the television had no internet connection.
When connectivity returned, the stored data could then be retrieved.
That does not mean every LG TV is secretly recording everything people say in the living room.
It means the microphone and operating system can become a surveillance capability after compromise.
LG strongly disputes the interpretation that its TVs routinely record ambient conversations. The company says voice processing occurs when users activate the relevant voice functionality or wake-word feature, with wake-word processing performed locally.
That distinction matters.
The security problem is what happens if an attacker gets control of the TV.
RCE Changes the Equation
The researchers also reported remote-code-execution vulnerabilities in webOS to LG.
The technical details have not been publicly released while responsible disclosure continues.
That means the most dangerous part of the research is currently incomplete.
If an attacker can remotely compromise a television, the device suddenly becomes much more interesting than an entertainment appliance.
It has:
- a microphone;
- network access;
- stored data;
- a browser and applications;
- visibility into the local network;
- access to other connected devices.
A successful compromise could therefore turn a TV into a foothold.
The microphone is just one possible consequence.
ACR Is Another Story
LG also uses Automatic Content Recognition, or ACR.
The technology samples what appears on the screen and creates fingerprints that can identify programs, advertisements and other content.
Researchers found ACR-related data collection across different usage scenarios, including content coming through external inputs such as HDMI.
This is not unique to LG.
Other smart-TV manufacturers use similar technology.
The security concern is what happens when extensive telemetry meets a compromised device.
A TV that already knows what you watch and what devices are around you becomes considerably more valuable to an attacker.
The Network Is the Bigger Prize
The most interesting part of the research may actually have nothing to do with the microphone.
It is the network map.
Imagine compromising a TV and immediately discovering:
192.168.1.12 — iPhone
192.168.1.20 — Windows PC
192.168.1.31 — NAS
192.168.1.40 — printer
192.168.1.50 — smart camera
The television does not need to compromise all of them.
It only needs to become the attacker’s starting point.
That’s why IoT isolation exists.
What LG Owners Should Do
Install the latest available webOS firmware.
Then go through the privacy settings and disable features you do not need, particularly optional ACR, personalized advertising and voice-related functionality.
More importantly, put the TV on a separate IoT or guest VLAN if your router supports it.
Your television does not need unrestricted access to your NAS.
It does not need to see your work laptop.
And it certainly does not need to sit beside your backup server on the same flat network.
If the TV gets compromised, segmentation limits what happens next.
Bugstoday Opinion
The uncomfortable lesson isn’t that LG made a TV that can record audio.
The uncomfortable lesson is that we keep treating televisions like appliances while manufacturers keep turning them into networked computers with microphones, telemetry and advertising infrastructure.
LG disputes the most alarming interpretation of the findings.
Fair enough.
But the researchers still demonstrated something important: once an attacker controls the television, capabilities that looked like harmless smart-TV features become security primitives.
The TV in your living room is no longer just watching television.
It is part of the network. Treat it accordingly.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
- Gamers Nexus / Level1Techs — LG Smart TV security and privacy investigation
- Malwarebytes — LG TV flaws and standby audio analysis
- LG — Statement regarding voice-data collection and network discovery
- LG webOS — Security updates and firmware




