LG’s Smart TV Security Is a Joke, and Your Living Room Pays the Price

Written by

in

TLDR

LG says its normal smart TVs do not continuously record ambient conversations. Fine. That does not make the security story reassuring.

Gamers Nexus, Level1Techs, and independent security researchers reported vulnerabilities that could turn tested LG televisions into covert listening devices. Researchers demonstrated microphone capture on a compromised TV, including while the display appeared off, and showed audio could be retained while the TV was offline and recovered after connectivity returned. The team also reported remote-code-execution vulnerabilities that were still going through responsible disclosure.

So LG’s defense boils down to an incredibly low standard:

Don’t worry. We aren’t necessarily spying on you ourselves. Our poorly secured television may merely be capable of becoming a bug in your living room if somebody compromises it.

Wonderful.

The focus keyphrase here is LG smart TV security, and the picture emerging in September 2026 is ugly.

A modern LG television is not just a panel.

It is a networked computer.

It runs webOS. It connects to cloud services. It scans the local network. It supports advertising technology. Some models contain microphones. It can process voice commands. It has access to whatever you plug into it.

That makes security critically important.

And researchers just demonstrated why consumers should stop treating smart TVs like harmless appliances.

LG Smart TV Security Is Not Some Side Issue

LG would probably prefer to divide this controversy into convenient little boxes.

Privacy over here.

Advertising over there.

Voice recognition somewhere else.

Security vulnerabilities in another department.

Consumers shouldn’t accept that framing.

These systems all live inside the same device.

A microphone becomes much more dangerous when the computer controlling it has exploitable security flaws.

Network scanning becomes much more concerning when an attacker could potentially compromise the device performing that scanning.

Locally stored information becomes more sensitive when malicious code might gain access to it.

And an internet connection becomes an exfiltration route.

That is why privacy and security are inseparable on something like a smart television.

LG can have the world’s most beautifully written privacy policy. It doesn’t mean much if the software underneath it can be hijacked.

Gamers Nexus Didn’t Just Complain About LG. Researchers Attacked the TVs.

The September 2026 Gamers Nexus investigation was conducted with Level1Techs and independent security researchers.

According to Gamers Nexus, the team tested LG Smart TVs and found both invasive first-party behavior and separate security vulnerabilities that could be exploited to turn televisions into covert listening devices.

That distinction is extremely important.

Some findings concern things LG intentionally designed the television to do, such as Automatic Content Recognition and network discovery.

Other findings concern what a malicious actor could make the television do by exploiting security vulnerabilities.

LG’s response has focused heavily on the first question:

Does a normal, uncompromised TV constantly record conversations?

LG says no.

But the second question is at least as important:

Why the hell can an attacker turn your TV into a listening device?

LG’s denial does not make that question disappear.

Researchers Demonstrated Microphone Capture on a Compromised LG TV

Malwarebytes summarized one of the most serious findings.

Researchers demonstrated that a compromised LG television could capture audio through its microphone, including while the television appeared to be off.

They also demonstrated audio capture while the television was disconnected from the network, with the information later retrievable after connectivity returned.

That is a nightmare scenario for a device sitting in a living room, bedroom, office, conference room, hospital, hotel, or business.

The television does not need to look suspicious.

It doesn’t need a blinking red light saying:

ATTENTION: YOUR TELEVISION IS CURRENTLY ACTING AS A MICROPHONE FOR AN ATTACKER.

It can just sit there.

Looking like a TV.

That’s exactly why security failures involving microphones are so serious.

LG Says Normal TVs Don’t Record Ambient Conversations

LG strongly disputes the idea that ordinary, uncompromised televisions continuously record conversations.

Its response says voice information is processed when a user presses and holds the microphone button on the remote or when an enabled far-field voice system recognizes a wake word such as “Hi LG.”

LG says wake-word detection occurs locally. If the wake word is not recognized, LG says the audio is immediately deleted and isn’t transmitted to its servers.

That’s an important response.

And there is no reason to pretend LG didn’t make it.

The most dramatic microphone demonstration in the Gamers Nexus research involved a compromised TV. Malwarebytes specifically updated its article to make that distinction clear.

So the responsible conclusion is not:

Every LG television secretly records everything you say 24 hours a day.

The responsible conclusion is:

Researchers demonstrated that LG’s television security could be defeated in a way that gave the compromised device disturbing surveillance capabilities.

That’s bad enough.

“An Attacker Did It” Is Not a Defense of LG

This is the part of LG’s response that drives me crazy.

The distinction between native behavior and compromised behavior matters when determining whether LG itself is secretly recording you.

It does not absolve LG of responsibility for the security of its product.

Imagine an automaker responding to a remotely exploitable car vulnerability by saying:

“Just to clarify, we don’t intentionally steer customers into traffic. An attacker would have to exploit the car first.”

Yes.

That’s the fucking problem.

Security vulnerabilities are not outside the manufacturer’s responsibility.

They are the security failure.

An internet-connected television with microphone access should be hardened against exactly this kind of abuse.

Researchers Also Found Plaintext Voice Transcripts

The investigation went beyond theoretical microphone access.

The Register reported that Gamers Nexus found plaintext transcripts generated from audio captured by the TV while inspecting the televisions’ internal data and network behavior.

Plaintext is exactly what it sounds like.

Readable text.

Not some incomprehensible audio fingerprint used only to match a movie.

Actual transcribed words.

That raises obvious questions.

How long can transcripts exist?

What processes can access them?

What permissions protect them?

Can a compromised process read them?

Could sensitive information spoken after a voice command end up inside a transcript?

Researchers have alleged that capture can extend beyond the exact spoken command.

LG disputes the characterization that televisions routinely collect ambient conversations.

Again, fine.

Then LG should provide detailed technical documentation showing exactly where the capture window begins and ends, where transcription happens, what gets retained, and what security boundaries prevent misuse.

“Trust us” isn’t good enough anymore.

Remote Code Execution Is the Phrase LG Owners Should Care About

The researchers also reported remote-code-execution vulnerabilities to LG.

Full exploit details were not publicly released because those vulnerabilities were still going through responsible disclosure.

Remote code execution is exactly the kind of vulnerability you don’t want in an appliance that:

  • has microphones
  • sits inside your home
  • connects to your LAN
  • discovers other devices
  • stores information
  • reaches the internet
  • receives software updates
  • may remain partially active in standby

A vulnerability does not automatically mean every LG TV can be compromised by anyone anywhere on Earth.

Attack requirements matter.

Firmware versions matter.

Network positioning matters.

Exploit details matter.

But the fundamental security issue is serious.

Researchers found ways to make a television do things its owner absolutely did not buy it to do.

LG Has Not Publicly Answered the Security Question Nearly as Well

LG’s public statements have been much more specific about voice collection and ACR than about the reported vulnerabilities themselves.

Malwarebytes noted in its September 10 update that LG had disputed the ambient-recording claims and confirmed network scanning, but had not publicly addressed the reported security vulnerabilities, which remained in responsible disclosure.

That’s the part I’d like LG to spend less PR language and more engineering detail on.

What vulnerabilities were found?

Which models are affected?

Which webOS versions are affected?

Can the flaws be exploited remotely?

Can they be exploited from the local network?

Have patches been developed?

Have they been deployed?

Are affected televisions still vulnerable?

How long did the vulnerabilities exist?

Did LG know about any of them before the disclosure?

Those are questions that matter more than issuing a broad statement that LG doesn’t spy on customers.

A TV With a Microphone Needs Better Security Than This

LG put the microphone there.

LG built webOS.

LG controls the update system.

LG designed the network functionality.

LG designed the voice stack.

LG chose how much functionality remains active in standby.

LG sells the device.

So when researchers turn the television into a listening device, LG doesn’t get to act like some unrelated third party wandered into the story.

This is their product.

And consumers have every right to judge them on how difficult it is to abuse.

A television with no microphone cannot be turned into a room microphone through software.

A television with a microphone can.

That doesn’t mean microphones should never exist.

It means adding one creates a security responsibility.

The LAN Scanning Makes a Compromised TV Even More Disturbing

The same investigation found that LG televisions could enumerate devices across the local network.

LG acknowledges network discovery but says it exists for ordinary functions such as connectivity, content sharing, and smart-home integration.

That may be legitimate during normal operation.

Now consider it from the attacker’s perspective.

A compromised television sitting on a flat home or business LAN may be positioned to observe or probe:

  • laptops
  • desktop PCs
  • phones
  • network storage
  • printers
  • routers
  • smart-home hardware
  • servers
  • cameras
  • other IoT products

The exact reach of a real exploit depends on network configuration and vulnerability specifics.

But that’s why security professionals preach least privilege and network segmentation.

A compromised TV shouldn’t have a front-row seat to the rest of your digital life.

This Is Especially Ugly in Offices and Conference Rooms

Home users are bad enough.

Now think about businesses.

How many conference rooms contain smart televisions?

How many have built-in microphones?

How many are connected to the same corporate network used by employee laptops?

How many display confidential presentations?

How many sit ten feet from meetings where executives discuss pricing, litigation, acquisitions, layoffs, contracts, customer information, or unreleased products?

Probably a lot.

And how many IT departments treat that television with the same seriousness as a laptop?

Probably fewer.

A compromised listening device permanently mounted to a conference-room wall is a much different security threat than another annoying piece of consumer ad tech.

LG’s Advertising Business Makes the Whole Thing Feel Even Dirtier

Security vulnerabilities would be bad enough if LG Smart TVs otherwise behaved like restrained appliances.

They don’t.

LG also operates an advertising ecosystem using Automatic Content Recognition data and other signals to understand television audiences.

Gamers Nexus says LG’s first-party ACR behavior can reveal more about household viewing activity than many owners realize.

LG says these advertising and ACR functions depend on user consent.

Still, putting all of these systems together creates exactly the kind of sprawling attack surface consumers should distrust:

Advertising.

Viewing recognition.

Voice processing.

Device discovery.

Cloud communication.

Smart-home integration.

Local storage.

Microphones.

Every additional feature creates more code.

More code creates more bugs.

More privilege creates more consequences when those bugs become security vulnerabilities.

At some point “smart” stops meaning useful and starts meaning needlessly dangerous.

LG’s Security Story Should Make You Treat the TV as Hostile

Until LG provides more technical transparency and the disclosed vulnerabilities are fully addressed, I would treat an LG Smart TV the same way I treat any questionable IoT product.

Isolate it.

Put it on a guest network or dedicated IoT VLAN.

Do not give it unrestricted access to computers and storage devices.

Disable voice functionality you don’t need.

Disable ACR and optional viewing-information agreements if you don’t want them.

Keep the firmware updated.

And if you don’t need webOS at all, consider keeping the television offline and feeding it HDMI from another device.

None of these steps creates perfect security.

But they reduce the amount of damage the TV can do if something goes wrong.

The Smart Part of the TV Should Not Be the Security Liability You Paid Extra For

LG makes excellent display panels.

That’s what makes this so infuriating.

People buy an expensive OLED because they want a beautiful picture.

They shouldn’t have to become network-security administrators because LG decided the television also needed to be an advertising platform, smart-home hub, voice assistant, telemetry source, streaming computer, and network-discovery appliance.

Complexity isn’t free.

The cost gets paid in bugs.

And sometimes the customer pays that cost with privacy.

LG’s Defense Does Not Make This Better

Let’s accept LG’s strongest argument.

LG itself is not intentionally recording ordinary ambient conversations all day.

Wake-word processing behaves the way LG says.

ACR requires consent.

Network scanning exists for legitimate smart-device functionality.

Fine.

Now we’re left with this:

Researchers found security vulnerabilities that they say could turn LG televisions into covert listening devices.

They demonstrated microphone capture on a compromised unit.

They reported remote-code-execution flaws.

The television can already discover other devices on the LAN.

And LG hasn’t publicly explained the underlying vulnerabilities in detail while responsible disclosure continues.

That’s still atrocious.

The distinction protects LG from one accusation.

It does not magically turn its security situation into something acceptable.

LG Smart TV Security Deserves Far More Scrutiny

Consumers should expect better from a company selling devices designed to sit inside private homes for years.

Not perfection.

Software has bugs.

Security researchers will always discover vulnerabilities.

What matters is the architecture, severity, response, disclosure, patching, and amount of unnecessary privilege the product had in the first place.

LG has stuffed its televisions full of capabilities that create enormous privacy consequences when security fails.

Then researchers showed those consequences aren’t hypothetical.

So no, the proper response isn’t:

“LG says it doesn’t normally record ambient conversations, so everything is fine.”

The proper response is:

Why did LG sell a network-connected microphone-equipped television that researchers could convert into a covert listening device at all?

Until LG provides a convincing technical answer, its smart-TV security deserves ridicule, anger, and serious scrutiny.

Because a $3,000 television should not double as an attacker-controlled bug in your fucking living room.

FAQs

Do LG TVs continuously record conversations?

LG says no. It says voice data is processed when the remote’s microphone button is held or when an enabled far-field system detects “Hi LG.” LG says unrecognized wake-word audio is processed locally and deleted.

Did researchers make an LG TV record ambient audio?

Yes. Researchers demonstrated microphone capture on a compromised television. Malwarebytes specifically notes that this demonstration does not establish that ordinary uncompromised TVs routinely record conversations.

Were LG security vulnerabilities found?

Researchers reported remote-code-execution vulnerabilities affecting tested LG televisions. Details remained under responsible disclosure when the investigation was published.

Did researchers find voice transcripts?

The Register reports that the investigation found plaintext transcripts generated from audio captured by the TV. LG disputes claims that its televisions routinely record ambient conversations.

Should an LG TV be isolated from other devices?

Network segmentation is a reasonable security precaution. Putting smart TVs and other IoT devices on a separate guest network or VLAN limits their ability to communicate directly with sensitive computers and servers if the device is compromised.

References

Gamers Nexus, 216,000,000 Spy TVs | The LG Smart TV Problem, September 6, 2026.

Malwarebytes, LG TV Flaws Could Let Attackers Listen In, Even in Standby Mode, September 7, 2026, updated September 10.

The Register, LG Accused of ‘Egregious Invasion of Privacy’ Over TV Data Collection, September 8, 2026.

Ars Technica, LG TV Shown Scanning LAN for Third-Party Phones and Other Devices, September 8, 2026.

Al Jazeera, LG Defends Smart-TV Features Amid Audio Surveillance Allegations, September 10, 2026.

Intent Sentence

This opinion piece helps LG Smart TV owners understand the security findings behind recent microphone-surveillance concerns by separating normal LG functionality from exploit-enabled behavior and explaining why a television that can be turned into a listening device is a serious consumer-security failure.

SEO Pack

SEO Focus Keyphrase:
LG smart TV security

SEO Title:
LG Smart TV Security Is a Joke

Meta Description:
LG smart TV security flaws could turn a television into a listening device. Here’s what researchers demonstrated and why LG’s defense falls short.

Slug:
lg-smart-tv-security-flaws

Excerpt:
LG denies that normal TVs constantly record conversations. Researchers still demonstrated security flaws capable of turning a compromised television into a covert listening device.

SEO Tags:
LG smart TV security, LG TV vulnerability, LG microphone spying, webOS security, Gamers Nexus LG, LG privacy, smart TV security