An investigation published in the first week of September has put LG televisions at the center of one of the most serious privacy controversies of the year. The US hardware channel Gamers Nexus, run by Steve Burke, worked together with Level1Techs, the team led by Wendell Wilson, and a group of independent security researchers to analyze several store-bought OLED sets from the brand, including the G3 and the G5, the 2025 flagship model. According to the team, the work took around 500 hours, and the result is a video running over two hours that documents what data these TVs collect, when, and where they send it.
Its conclusions have two levels that shouldn’t be mixed together. On TVs straight out of the box, researchers confirmed that they scan the home network to identify connected devices and that the content-recognition system keeps running even when the TV is used purely as an HDMI display. Then, in a second step, exploiting vulnerabilities in the webOS operating system, they showed that a compromised TV can be turned into a remote microphone while the screen appears to be off.
LG denies the core accusations. It maintains that its TVs do not record conversations from the home and that viewing-data collection only activates with explicit consent. The scale of the issue explains the uproar: LG has around 216 million smart TVs in use worldwide, 49 million of them in the United States.
What was confirmed on TVs straight out of the box
The most solid part of the investigation, and the one LG doesn’t really dispute, is the part that affects any unmodified TV.
An inventory of everything in your home
Through network traffic captures and firmware analysis, the researchers observed that the TVs sweep the local network and catalog what they find: phones, computers, smartwatches, printers, network switches, servers, and even climate-control equipment. For each device they log the name, the internal IP address, and identifiers derived from the MAC address, the unique serial number of the network card.
“The [G5] crawled our entire network and found dozens of unrelated devices, including smartwatches and phones of our staff who didn’t even know we were working on this,” Burke explained. And he underscored the most important nuance: “This is the TV’s native functionality. This didn’t require vulnerabilities.”
They don’t stop at your own network, either. The TVs also collect the names of nearby Wi-Fi networks and their signal strength — meaning your neighbors’ networks. According to the investigation, all of this happens without any configuration: just plugging in the TV is enough.
Content recognition doesn’t switch off with HDMI
The technology in question is called ACR, short for automatic content recognition. It works by sampling what appears or plays on the TV, generating a digital fingerprint, and comparing it against a reference database to identify what’s being watched: a show, an ad, a movie, or a video game.
The key finding is that on the TVs tested, ACR runs as a background process, independent of whichever input is active. In other words, it kept working when the TV was acting as a plain display for a console or a computer connected over HDMI, not just with the TV’s own apps. “Even using an LG smart TV as a dumb monitor doesn’t necessarily stop all of the functionality we’re talking about today,” Burke summed up. The researchers also logged a steady stream of data flowing to LG Ad Solutions, the company’s advertising division.
More devices than TVs
Gamers Nexus ties that inventory back to the advertising business. LG Ad Solutions boasts in its sales materials of being able to reach 363 million “addressable secondary devices” in the United States — a figure far higher than the 216 million smart TVs the brand has worldwide. For the team, scanning the home network could explain that gap. The video also resurfaces comments from an LG Ad Solutions executive in an industry interview: “We know who is in the LG household, we know which devices are there, we know how to extend that reach into mobile.”
Burke sums it up this way: some of these companies now make more margin from targeted advertising than from selling the TV itself.
What was only shown on a compromised TV
The most alarming part of the investigation is also the one that demands the most precision, because it doesn’t describe the TV’s normal behavior.
The researchers found remote code execution vulnerabilities in webOS services exposed to the network. They reported them to LG following responsible disclosure procedures: they haven’t published the technical details or the vulnerability identifiers, to give the company time to release a patch first.
Exploiting those flaws, they took control of an LG G5 and turned it into a listening device. With the screen black, as if it were off, the TV picked up intelligible audio through its built-in microphone. When they unplugged the network cable, it stored the recording locally; once reconnected, it sent it out.
“We were able to retrieve plain text transcriptions of voice conversations and inputs from the TV, [and] use the TV to record from a webcam and from a microphone while the TV appeared to be off. And it was a clean capture, too,” Burke said. The team says that among what was captured in plain text was even a Social Security number, that some of the material was too sensitive to air, and that after disabling the TV’s main microphone, they found another working microphone in the remote. “It doesn’t cost a lot to store text forever,” Wendell Wilson noted.
The conclusion to draw isn’t that LG TVs record by default, but something different and just as worrying: a TV with a microphone permanently connected to the network is an attractive target, and if someone manages to take control of it, the microphone works in their favor. Until a patch exists, the security of those models depends on the flaws not being exploited. That’s why the researchers involved in the work recommend disconnecting LG smart TVs from the network, and Burke warns that pulling the ethernet cable might not be enough if the TV still has Wi-Fi access.
The investigation also states that once voice recognition activates, the capture window stays open for about 10 to 15 seconds after the person stops talking, and that what’s captured gets transcribed and stored in the TV’s own logs, in plain text. LG doesn’t deny that window exists, but frames it differently, as explained below.
What LG says in response
The company first reacted with a brief statement and, on September 12, followed up with a longer official statement on the privacy of its TVs.
“The claims are not true”
In its first response, LG called the claims in the Gamers Nexus video false and said its TVs only process voice data in two cases: when the voice button on the remote is held down, or when they detect a wake word like “Hi LG” after the user has turned on far-field voice recognition. “Other than these instances, the TVs do not collect or record ambient conversations,” it stated.
As for the network scan, LG doesn’t deny it: it describes it as a standard feature for detecting and connecting other devices in the home, common to TVs and smart home appliances. And regarding ACR, it noted that it’s offered on an opt-in basis for recommendations, services, and personalized advertising.
The September 12 statement, point by point
Voice. Voice recognition is off by default and only works if the voice information agreement has been accepted. Wake-word detection happens on the TV itself, and audio that doesn’t contain it is not stored, not transcribed, and not sent. Speech-to-text conversion only starts after the wake word is recognized, and each session is capped at around 18 seconds. On compatible models, the microphone can be turned off with a physical switch.
ACR. LG describes it as a feature that is optional and off by default, requiring acceptance of the viewing information agreement. According to the company, it uses audio fingerprints to identify content and does not collect voice recordings, other audio recordings, screenshots, or video. Interest-based advertising requires separate consent, and both can be withdrawn at any time from the settings. Turning it off stops the data collection.
Network and partners. Information about detected devices is not used to profile households, for cross-device advertising, or for audience segmentation. ACR data can be shared with LG Ad Solutions for audience analysis, but voice and ambient audio data are not.
Security. LG runs a bug bounty program, works with outside researchers, and provides security updates for up to five years from each compatible model’s launch.
Gamers Nexus didn’t consider the matter closed: it responded with a new video calling LG’s reaction manipulative and standing by all of its conclusions. The team has also announced it will push for laws to protect people who buy this kind of device.
Where the two versions actually clash
Read calmly, the investigation and LG’s response agree on more than it seems. The real disagreement comes down to three specific points.
The network scan itself isn’t in dispute — its scope is. Both sides agree it exists. The disagreement is over whether collecting device names, network identifiers, and neighbors’ Wi-Fi networks is the bare minimum needed to connect devices, or something that goes further. LG says that data isn’t used for advertising purposes; Gamers Nexus hasn’t published direct proof that it is, but it has shown that it’s collected.
ACR: “off by default” versus “running.” LG says it’s optional; Gamers Nexus found it active. Both things can be true at once if consent is given during the TV’s initial setup, where it’s common to accept several agreements in a row. That is exactly the question the Texas settlement already addressed: how clear that consent really is.
Audio: normal behavior versus risk. LG describes how an unmodified TV behaves. The listening demonstration with the screen off was carried out on a compromised TV. The two don’t actually contradict each other: the company is talking about the design, the researchers about the risk of an attacker exploiting it. What remains open is when the patch for the reported vulnerabilities will arrive.
The precedent: the Texas settlement
The investigation doesn’t arrive out of nowhere. On May 11, 2026, Texas Attorney General Ken Paxton announced a settlement with LG Electronics over its use of ACR to collect viewing data from state residents without their informed consent.
Under the announced terms, LG commits to not collecting viewing data through ACR without informed consent, to displaying a pop-up notice on its TVs explaining how that data is collected and used, to publishing that same information on its website, to offering a clear and simple way to opt out of the collection, and to banning any transfer of viewing data to the Chinese Communist Party. LG did not admit any liability or wrongdoing.
The settlement is part of a broader lawsuit the attorney general’s office filed in December 2025 against five manufacturers it accused of spying on Texans inside their own homes: Samsung, Sony, LG, Hisense, and TCL. Samsung had already reached a settlement before LG; the cases against Sony, Hisense, and TCL remain open.
What could come next
After the investigation was published, several US law firms have opened investigations into possible class-action lawsuits. One is looking into whether certain LG TVs collect audio, identify devices on the home network, and send that information to the company without users understanding the real scope of the collection. Another is examining the situation of owners who were reportedly asked to accept new privacy terms in order to install mandatory software updates.
For now, there are no known official reactions from data-protection authorities outside the United States, nor a timeline for the vulnerability patch. The two fronts, legal and technical, are the ones that will decide how far the case goes.
What you can do with an LG TV
Anyone with an LG TV at home can reduce their exposure without giving up the television, and most of the steps match what the company itself describes in its statement:
- Install firmware updates as soon as they’re available. It’s the only defense against the reported vulnerabilities, though it doesn’t change the data collection that’s built into the design.
- Review the agreements accepted in the settings and withdraw the viewing information agreement, which disables ACR, along with the interest-based advertising agreement.
- Turn off voice recognition and the wake word if you don’t use them, and, on models that have one, switch off the microphone with its physical switch.
- Connect the TV to a separate network, such as the router’s guest network or one set up specifically for smart devices, so it can’t see the rest of the devices in your home.
- Turn off UPnP on the router, which lets devices open ports to the internet on their own.
And a radical option that works with any brand: use the TV without connecting it to the internet and keep the apps on an external console or streaming device. Keep in mind, though, that according to the investigation the TV can store data while disconnected and send it once reconnected, so for this to work it has to stay disconnected permanently.