Recent investigations reveal LG smart TVs may be collecting far more user data and possess security flaws that could enable remote intrusions, raising significant privacy and security concerns for consumers.
An investigation into LG smart TVs has raised two separate questions at once: whether the sets collect far more information than most owners realise during ordinary use, and whether that data becomes especially sensitive if attackers exploit still-undisclosed webOS flaws. Gamers Nexus, working with Level1Techs and independent researchers, said on 7 September that retail OLED sets including an LG G5 could capture microphone audio while the screen was in standby, keep clips locally when the network cable was removed, and transmit them after connectivity returned. Reports published later that day said LG had not yet publicly answered the new allegations. (notebookcheck.net)
Another strand of the testing suggested the television behaves less like a single-purpose display than a networked scanner inside the home. According to reporting on the investigation, one set detected at least 38 other devices on its Wi-Fi network, including phones, smartwatches, servers, printers and thermostats. Researchers said the TV could enumerate internal IP addresses, device names and usernames, while packet captures also showed collection of neighbouring wireless network names, signal strengths and location-related data. That matters because such telemetry can sketch a detailed map of a household even before any viewing data is added. (dexerto.com)
That commercial layer is central to the story. LG Ad Solutions says its advertising platform reaches 49 million LG smart TVs in the US and 216 million globally, and advertises access to 363 million US addressable secondary devices. TechRadar highlighted marketing language in which LG tells advertisers “we know who’s in the LG household” and can extend campaigns beyond the television to other screens. Reporting on the Gamers Nexus tests said LG’s Automatic Content Recognition system fingerprints audio and video across inputs, including HDMI, meaning a streaming box or games console does not necessarily stop the set from learning what is on screen. (lgads.tv)
On its own, that is a privacy controversy. Combined with the security findings, it becomes a more serious network risk. Notebookcheck said the researchers documented remote-code-execution weaknesses in webOS and are still handling them through responsible disclosure, so full exploit details have not been released. Dexerto reported that the team also demonstrated how a hijacked set could be used to activate its microphone or a connected webcam while the panel appeared to be off. In that scenario, the TV is not merely gathering advertising data; it could become a listening point and an entry route into the wider home or office network. (notebookcheck.net)
LG’s public position has not been consistent with the impression left by the investigation. In a statement previously given to TechRadar, the company said its TVs “do not collect, record, or store ambient conversations” and described voice recognition as an optional, user-initiated feature. LG also said customers can use smart TV features without enabling voice recognition. Yet the company’s updated US terms say that, depending on the environment, nearby voices from family members, guests, children and bystanders may be recorded and analysed for AI-based services, and an LG support page states that agreements covering viewing information, voice features and personalised ads are optional rather than required for basic smart services. (techradar.com)
The dispute arrives only months after LG agreed to settle privacy claims brought by the Texas attorney general over automatic content recognition. In an 11 May 2026 announcement, the state said LG would stop collecting viewing data through ACR without informed consent and would add clearer disclosures and opt-out choices. The present allegations also follow a separate July row over LG monitor software and revised terms that drew attention to the company’s voice-related clauses, including wording that places responsibility on owners to obtain consent from other people whose voices may be captured. (oag.state.tx.us)
For owners, the practical question is what to do now. The most hard-line recommendation reported from the testing team was to keep the television off the internet and use an external streaming device instead. Short of that, LG’s own support material says optional agreements for viewing information, voice features and personalised ads can be declined, and security guidance around the investigation has focused on prompt firmware updates, putting televisions on a separate guest or IoT network, and limiting router features such as universal plug and play that expose services unnecessarily. (notebookcheck.net)
No public technical advisory from LG addressing the 7 September investigation had been identified in reports published on Monday, and the researchers have not published the full vulnerability chain while disclosure continues. That leaves consumers with an awkward conclusion: the same screen sold as a premium living-room device is also part advertising endpoint, part network client and, if the security claims are confirmed in full, a potentially valuable foothold for intrusion. For regulators and buyers alike, the issue is no longer just what a smart TV shows, but what it notices, stores and can be made to reveal. (notebookcheck.net)
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





