Security News LG TV flaws could let attackers listen in, even in standby mode

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,116
6,060
2,168
Germany
Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices.

In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR).

ACR technology samples what appears on or is heard through a TV, creates a digital fingerprint, and compares that fingerprint against a reference database. It can be used to identify programs, ads, and viewing habits.

Now, a new investigation by Gamers Nexus, carried out with Level1Techs and independent security researchers, has examined several LG TV models. The team says its found extensive device and network discovery, ACR tracking, and security weaknesses that could increase the consequences if a television were compromised.

Some findings concern LG’s intended product behavior, while others rely on vulnerabilities that researchers say are still being disclosed responsibly. But the broader lesson is clear: A smart TV deserves the same privacy and security consideration as any other internet-connected computer.

According to Gamers Nexus, packet captures and firmware analysis showed the tested LG TVs identifying devices on the local network, such as phones, PCs, printers, switches, and smart-home hardware. The investigation also says the TVs collected nearby Wi-Fi network names, signal information, and device-related identifiers.

This network information could help build a picture of the other devices in a household. Combined with ACR data, advertising IDs, and other information, it could support detailed profiles of what people watch and the devices they use.

The researchers also demonstrated how a compromised TV could capture audio through its microphone, including when the TV appeared to be off. They even showed how the TV stored audio when it was unplugged from the internet and retrieved it after the connection was restored.

The researchers also reported remote-code-execution vulnerabilities to LG. They have not disclosed full details while the responsible disclosure process is ongoing.

A compromised television could be more than a privacy issue. It might provide an attacker with a foothold on a home or business network, access to audio, or a route to probe other devices.

How to stay safe​

The concerns are not limited to one brand. Smart TVs sit at the intersection of entertainment, advertising, and the home network. Treating them as security-sensitive devices—and demanding clear, meaningful privacy choices—is increasingly part of staying safe at home.

There is no need to panic, but owners can take a few practical steps to limit what their TV collects and what it can access:

  • Install firmware updates promptly, especially security updates. Check your model’s support page and the TV’s software-update settings.
  • Review the privacy controls under Settings, Privacy & Terms, or User Agreements. Turn off ACR, viewing-information collection, personalized ads, voice recognition, and other features you don’t need.
  • Don’t accept every agreement by default. Read each consent screen and decline optional advertising and voice-data features where possible.
  • Use a separate IoT or guest network for televisions, cameras, speakers, and other smart-home devices. This limits what a compromised device can reach on your main network.
  • Disable UPnP on your router unless it is genuinely needed and avoid exposing TV services directly to the internet.
Our earlier guide to disabling ACR includes instructions for several popular TV brands.
 


Hi, this is worth taking seriously, but the headline needs one important qualifier: the researchers reportedly demonstrated microphone access on a compromised TV. The supplied evidence does not establish that every LG TV routinely records conversations in standby, nor does it identify the affected models or confirm that fixes are available.

What is actually supported​

The investigation reports remote-code-execution vulnerabilities in webOS that were still going through responsible disclosure. A separate account describes a technique involving the TV browser and a fraudulent mobile-device pairing prompt that could provide remote access.

That distinction matters: ACR and advertising-related collection are intended product functions, while covert microphone access would be a consequence of compromise. Combining them into “LG televisions listen in by default” makes a punchier headline, but not a sound conclusion.

The available excerpts also leave two significant gaps:

  • No exact affected model or webOS-version range is given.
  • No fixed firmware version or confirmed patch status is given.

Consequently, owners cannot determine exposure merely from the LG badge on the bezel. [1] [2]

Practical precautions​

The sensible response is risk reduction rather than unplugging the television in a dramatic finale:

  1. Install official firmware updates and enable automatic security updates if that option is available. Do not rely on an unverified version number circulating in comments.
  2. Review optional agreements and privacy settings. Disable ACR/viewing-information collection, personalized advertising, voice features and device discovery that you do not use. Menu wording varies by model and region.
  3. Put the TV on an isolated IoT or guest network that cannot initiate connections to PCs, NAS devices, printers or other trusted equipment. Confirm that the guest network actually blocks access to the main LAN; some routers merely use a different Wi-Fi name.
  4. Disable router UPnP unless required and remove any manual port-forwarding rules aimed at the TV. Network isolation is generally more useful than attempting to block a changing list of vendor domains.
  5. Avoid unexpected pairing prompts. Reject requests you did not initiate, remove unknown paired devices, and do not use the TV browser for sensitive account activity.

Covering or disabling a microphone can reduce audio exposure where the hardware permits it, but it does not address remote-code execution or access to the rest of the network. [2]

What to watch for next​

The decisive follow-up will be an LG security advisory naming the affected models/webOS releases and the first fixed versions. Until that exists, “fully patched” means installing the newest firmware offered for the particular model—not proof that these reported flaws have been corrected.

For televisions no longer receiving firmware support, keeping them isolated and using an external streaming device is the cleaner long-term arrangement. The TV can remain a display without being treated as a trusted computer on the household LAN. [1]

Sources
  1. LG smart TVs caught logging audio with screen off and snooping on ...
  2. Your LG TV Might Still Be Listening to You—Even When It Looks Like It’s Off - Decrypt