Gamers Nexus investigation uncovers ongoing privacy and security risks in LG smart TVs

An in-depth investigation reveals that LG’s smart televisions may continue to collect and store user data even when turned off, raising significant privacy and security concerns amid ongoing industry scrutiny.

An investigation by Gamers Nexus has raised fresh questions over how LG smart TVs handle data, with the video-based report saying some sets can continue to collect and store information even when they appear to be switched off or disconnected. Working with Level1Techs and independent security researchers, the channel said it spent more than 500 hours and about $70,000 testing retail LG televisions and found evidence of network scanning, audio capture and persistent tracking features that extend well beyond ordinary viewing functions.

The most striking claim is that LG’s Automatic Content Recognition system can still identify material played through HDMI inputs, not just through native streaming apps. Malwarebytes said the technology works by sampling audio and visual output, converting it into a fingerprint and matching it against a reference database, while TechRadar noted that privacy specialists have questioned whether consumers are given clear enough notice when the system is active. The investigation also said the televisions could map other devices on a home network using standard discovery protocols, widening the amount of household data exposed to the manufacturer and its advertising arm.

Gamers Nexus also said it obtained microphone audio from a set with the screen dark and, in one test, from a television that had been taken offline. According to the report, voice input was written to on-device logs, and audio could be stored locally before being uploaded once the set reconnected. That would appear to conflict with LG’s public denials, which Tom’s Hardware reported in response to the allegations; LG said voice processing only occurs when a voice assistant is manually activated or a wake word is detected, and that such processing is handled locally unless the user initiates it.

The privacy dispute comes only months after Texas Attorney General Ken Paxton announced a settlement requiring LG to secure informed consent before collecting Automatic Content Recognition viewing data and to provide a clear opt-out. TechRadar said privacy experts still see a gap between the way these systems are presented during setup and the extent of the data collection described in technical reviews. Gamers Nexus also said LG’s default settings still left the “Do Not Sell My Personal Information” control turned off before users had agreed to anything, a point likely to keep regulators and consumers focused on how consent is obtained in practice.

The broader security picture is equally uncomfortable. Malwarebytes said researchers identified unpatched remote-access flaws that could allow commands to be executed on a television over a network, while Krebs on Security reported that residential-proxy code had been found in a significant share of apps in LG’s webOS store. LG has said it is working with developers to remove the code or suspend affected apps, but the findings underline a wider problem for smart TVs: they are no longer passive display panels, but networked computers with microphones, ad systems and access to devices across the home.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.