LG Smart TVs Found Scanning Home Networks and Recording Audio Offline
A technical investigation reveals LG televisions act as active surveillance nodes, harvesting user data for advertising and exposing critical security flaws.
An investigation by GamersNexus and independent security researchers has revealed that LG Smart TVs function as pervasive surveillance devices within the home. The findings indicate that these televisions actively map local networks and record audio conversations, posing a significant risk to consumer privacy.
According to the research, LG Smart TVs continuously scan local networks to identify and map all connected devices, including smartphones and internal server infrastructure. The investigation further found that the devices can capture microphone audio even while the screen is off and while disconnected from the internet. This audio data is stored locally and then exfiltrated to LG servers once a network connection is restored. These capabilities are tied to Automatic Content Recognition (ACR), which LG uses to build detailed user profiles for targeted advertising.
The Data Monetization Model
This surveillance infrastructure supports a systemic business model where hardware serves as a gateway for data harvesting. The data collected from these televisions is monetized by LG Ad Solutions, a wholly-owned subsidiary of the company. The aggressive nature of this data collection is underscored by comments from Sergey Mata, President of LG Ad Solutions, who stated, "We own the glass. We own the TV."
Security Vulnerabilities
Beyond intentional data harvesting, the investigation uncovered a critical security flaw in the browser-service component of LG WebOS. This path-traversal vulnerability allows local attackers to bypass authentication entirely, granting them full root access to the device. Such a breach could allow a malicious actor to turn the television into a covert listening device or a pivot point for further attacks on the rest of the home network.
Industry Implications
These revelations shift the perception of smart TVs from passive displays to active network nodes capable of pervasive monitoring. The ability to record audio offline and map private network architecture is particularly dangerous in sensitive environments, such as corporate boardrooms, law firms, or medical offices, where confidentiality is paramount. The findings highlight a growing tension between manufacturer revenue streams and the fundamental right to privacy in the home.
What's Next
As these vulnerabilities become public, the industry is watching to see if LG will implement more transparent opt-out mechanisms for ACR and network scanning. While the technical flaws in WebOS require patching, the broader issue of integrated surveillance software remains a legal gray area, as current regulations often struggle to keep pace with the capabilities of embedded smart-home hardware.