LG smart TVs record with the screen off and scan your whole home network

An investigation published on 7 September 2026 by Gamers Nexus, in collaboration with Level1Techs and independent security researchers, has exposed the extent of background data collection by LG smart televisions.

Using packet capture analysis on a retail 2025 flagship LG OLED G5, the findings describe a device that spends its idle time surveying the network around it.

Network enumeration and the microphone exploit

Without ever being paired to the television, surrounding hardware was catalogued. Smartphones, watches, printers, routers, thermostats and computers sharing the Wi-Fi network were all enumerated. The set also collected IP addresses, location data, and the signal strengths and channels of nearby networks. LG defends these as standard smart TV behaviour.

The most striking claim involves the television’s built-in microphone capturing ambient audio while in standby mode, buffering it locally, and uploading it once internet access was restored. Some of the captured audio appeared as plain-text transcripts. These severe audio captures were executed on a compromised device. Researchers used remote code execution (RCE) flaws within LG’s webOS, which have been reported to LG and are awaiting patches.

This demonstrates two things: the hardware is capable of covert recording, and webOS contained security holes wide enough for someone else to trigger it. It does not prove that LG sets stream ambient conversations to the company by default. LG maintains its televisions “do not collect, record, or store ambient conversations”, stating voice data is only processed when the remote’s button is held or the “Hi LG” wake word is activated.

Data brokerage and supply chain flaws

While the microphone exploit requires a compromised system, automatic content recognition (ACR), branded as Live Plus, runs by default. It fingerprints on-screen content to identify viewing habits, affecting even external inputs like gaming consoles or decoders.

A 2024 academic study by University College London, UC Davis and Universidad Carlos III de Madrid, presented at the ACM Internet Measurement Conference, measured how often each manufacturer samples the screen. A July 2026 analysis by Spur unpacked 6,038 apps across the two app stores and found 2,058 carrying residential proxy code.

MetricLGSamsung
Screen sampling frequencyEvery 10 millisecondsEvery 500 milliseconds
Apps carrying residential proxy code42.5% of webOS apps26.9% of Tizen apps
Addressable televisions (US)49 millionNo equivalent figure gathered
Secondary devices tracked (US)363 millionNo equivalent figure gathered

Note: the last two rows are LG Ad Solutions’ own marketing figures and have no Samsung counterpart in this research. The secondary device figure is higher than the television figure because the television counts the unpaired mobile phones sitting near it.

This data collection feeds LG Ad Solutions, which sells audience reach to advertisers. Addressing the proxy apps, which route strangers’ web traffic through a user’s connection, LG senior vice president John Taylor said non-compliant apps will be suspended.

Regulatory backlash and local context

Regulators are pushing back against these practices. Texas attorney general Ken Paxton sued Samsung, LG, Sony, Hisense and TCL on 15 December 2025 over covert data collection. Following Samsung’s settlement on 26 February 2026, LG settled on 11 May 2026, agreeing to enforce informed consent, add on-screen disclosures and provide simple opt-outs. Yet Gamers Nexus found the “Do Not Sell My Personal Information” toggle remained off by default before the tested TV had even connected to the internet.

For Kenyan consumers, the Data Protection Act of 2019 makes consent one of the lawful bases for processing personal data, and the Office of the Data Protection Commissioner has issued penalties for mishandling it. We have not found any ODPC statement on smart TV data collection. Because the Texas settlement only legally binds LG in Texas, Kenyan owners fall into the same gap between having a law and using it that turned up with smartphone data practices.

Securing your home network

Four steps follow from the research:

  1. Disable Live Plus. Navigate to Settings, General, System, Additional Settings to turn off ACR. Switch off voice recognition and personalised adverts while you are there.
  2. Isolate the device. Put the television on a dedicated guest Wi-Fi network to stop it enumerating your laptops and primary devices.
  3. Update firmware. Install webOS updates as they arrive, because the RCE flaws are real and a patch is coming.
  4. The physical bypass. Gamers Nexus advised keeping the television off the internet entirely and using a dedicated, easily replaceable streaming box. An excellent OLED panel is still an excellent panel with the Wi-Fi switched off.

Source: https://tech-ish.com/2026/09/09/lg-smart-tvs-record-with-the-screen-off-and-scan-your-whole-home-network/

Join our
Mailing List

* indicates required
/ ( mm / dd )