A comprehensive investigation uncovers that LG’s webOS televisions are mapping home networks, capturing audio even when off, and potentially exposing households to security vulnerabilities, prompting calls for immediate user action and industry scrutiny.
LG is facing fresh scrutiny over the data collection and security design of its smart televisions after a lengthy investigation by Gamers Nexus, carried out with Level1Techs and independent researchers, found that some webOS sets mapped home networks and could be used to capture room audio while appearing to be switched off in standby. Decrypt reported that the team spent more than 500 hours and about $70,000 on the work. The timing is awkward for the company: on 11 May 2026, Texas attorney general Ken Paxton announced a settlement requiring LG to stop using automatic content recognition, or ACR, to collect viewing data from Texans without informed consent. As of Tuesday, 8 September 2026, several outlets said LG had not publicly answered the new findings.
What appears to be ordinary smart-TV telemetry was only part of the picture. Notebookcheck, citing packet captures taken with Wireshark, said retail LG OLED models including the G5 were seen scanning the local network for unrelated devices. Malwarebytes said the televisions identified phones, PCs, printers, switches and other smart-home equipment; Dexerto added servers and thermostats; Hartware mentioned games consoles. One test set reportedly discovered at least 38 other devices. According to Notebookcheck and Hartware, the TVs also collected nearby Wi-Fi names, signal strength and other identifiers that could help infer a household’s location and hardware layout.
That matters because the network inventory can be joined to the TV’s own viewing data. Malwarebytes said the device list could be combined with ACR, advertising IDs and other information to create a detailed profile of a home. Recordere.dk noted that ACR was already known to fingerprint what appears on screen, but said the new reporting pointed to a broader collection system. Decrypt said Gamers Nexus found LG’s ACR continuing to work even when a set was being used only as an HDMI monitor, rather than for built-in apps. Notebookcheck further reported that the data flow fed LG Ad Solutions, whose marketing materials claim access to 363 million “secondary addressable devices” in the US, while LG has said it has sold about 216 million smart TVs globally.
The commercial logic was stated unusually bluntly. Decrypt said LG Ad Solutions executives were shown describing the company as one that “owns the glass”, a remark used in an advertising context to describe control over the television as a route into the rest of the household. In that framing, the TV is not simply a screen. It becomes an identifier for other devices sharing the same network and a way to connect what people watch with the phones, computers and wearables around them.
The most sensitive findings concerned microphones, but the distinction between built-in behaviour and attack scenarios matters. Dexerto was right to note that the investigation does not prove LG televisions are continuously recording every private conversation by default. What the reporting does show is more specific. According to Decrypt, researchers muted the main microphone in software and still recovered usable audio from a second microphone that the mute control did not affect. Hartware said the microphone remained active for 10 to 15 seconds after someone stopped speaking, increasing the chance of collecting unintended speech. Dexerto also reported that, after voice recognition had been activated, a fake Social Security number spoken during testing was written into logs as plain text.
Several outlets said the televisions kept hold of data even after losing internet access. Malwarebytes, Recordere.dk and Hartware all reported that audio continued to be stored locally while a set was offline and was transmitted or retrieved after connectivity returned. Decrypt said one test recovered clean audio after the television had been disconnected from ethernet, and reported that speech was captured from roughly 60 feet away through a wall. Hartware and Dexerto said some speech and commands were converted into plain text logs on the device itself. In July, however, LG told reporters that its TVs “do not collect, record, or store ambient conversations.”
The security researchers also said the privacy issues were not only about authorised tracking. Notebookcheck, Malwarebytes and Hartware all said remote-code-execution flaws in webOS were disclosed to LG under a responsible disclosure process, with technical detail withheld while fixes are still being discussed. Malwarebytes warned that a compromised TV could give an attacker a foothold on a home or business network. Decrypt added that one attack chain involved tricking the TV’s browser into pairing with a fake mobile-device prompt, potentially handing over remote access without the owner realising.
The investigation does not establish that every LG television behaves identically, or that every region and webOS version is affected in the same way. Notebookcheck and Recordere.dk said the testing covered several retail OLED sets, including the G5 series, rather than the whole catalogue. Even so, the findings point to a familiar problem in consumer electronics: a television is now a networked computer with advertising software, app distribution, microphones and, in some cases, cameras, but it is still treated by many households as an ordinary display.
For owners, the immediate response is practical rather than theoretical. Malwarebytes urged users to install firmware updates promptly, review privacy settings carefully, and turn off ACR, personalised advertising and voice functions they do not need. It also recommended placing televisions on a separate guest or IoT network and disabling UPnP on the router unless it is genuinely required. Notebookcheck said the investigators’ own recommendation was more severe: keep LG sets off the internet and use an external streaming box instead.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





