LG Electronics is facing fresh allegations that its smart TVs harvest extensive data about users and their home environments, including capturing audio while in standby mode and continuing to record even after being disconnected from the internet.
The claims come from the Gamers Nexus YouTube channel, which published a 135-minute investigation detailing how retail LG OLED models scan local networks for nearby devices, log location data and Wi-Fi network details, and transmit the information to LG Ads Solutions, the company’s targeted advertising division.
Stephen Burke, editor-in-chief of Gamers Nexus, said the team collaborated with Level1Techs and independent security researchers to test retail units, including the G5 model. Packet captures taken through Wireshark allegedly revealed such a large volume of private data that it could not be fully displayed in the video, with Burke describing the findings as “an egregious invasion of privacy.”
The TVs were observed enumerating devices on the local network that had never been paired with them, including smartphones, smartwatches, routers, thermostats, air purifiers, server baseboard management controllers, and PCs. The sets also gathered IP addresses, location data, and the names, signal strengths, and channel numbers of nearby Wi-Fi networks.
Perhaps most striking was the claim that microphone audio capture continued while the display was in standby. When researchers disconnected the TV from Ethernet, the set kept saving voice input locally and uploaded the stored files once connectivity was restored, according to the investigation.
The ACR layer
Automatic Content Recognition, or ACR, forms another pillar of the data collection architecture. The technology samples on-screen audio and video to generate digital fingerprints that identify what users are watching across all inputs, including HDMI and other ports, not just content streamed through the TV’s own smart interface.
ACR is not unique to LG. A separate video from RTINGS examines how nearly every major smart TV manufacturer deploys some form of the technology, though the controls available to consumers vary by vendor. LG announced in 2022 that ACR previously limited to US sets would expand to televisions sold across 27 countries, with the resulting insights available through its advertising business.
LG has stated that its ACR data is anonymized and handled in accordance with privacy regulations, and that advertising customers can use the insights to measure campaign effectiveness.
What makes the feature hard to find is that no two manufacturers call it the same thing, and none of them file it under picture or sound. On every major platform it sits in the privacy, terms or diagnostics section of the settings menu, under a name that does not contain the words “tracking” or “advertising.”
BrandName of the ACR settingLGLive PlusSamsungViewing Information ServicesSony (Google TV)Samba Interactive TVVizioViewing DataTCL and RokuSmart TV Experience
Samsung’s control sits alongside a separate Interest-Based Advertising toggle; switching off one does not switch off the other. Setting names vary by model year and firmware version.
What the sets in Japanese living rooms do
For readers outside the United States the more useful question is what the television they actually own is doing, and in Japan the two largest domestic platforms both run viewing-data programmes of comparable ambition — with markedly more disclosure attached.
TVS REGZA collects second-by-second viewing data from more than five million sets nationwide and sells the resulting analysis to broadcasters and advertisers as a commercial service. The company states that it acquires no viewing history at all if the television is not connected to a network, or if the owner has not selected “agree” on the REGZA privacy policy presented when its cloud services are first set up, and it documents how to check or withdraw that consent later.
Sony’s Japanese programme, TV Viewing Connect, covers BRAVIA sets with Android TV or Google TV shipped since 2015, and its disclosure page itemises what is taken: programme name, viewing start and end times, recording reservations, the model number, a device identifier, the IP address with timestamp, and usage signals such as power on and off and how often the remote and programme guide are used. Notably, the same page states plainly that the content data covers video watched through externally connected equipment as well as broadcasts — the HDMI-input fingerprinting that sits at the centre of the LG dispute, spelled out on a dedicated page rather than buried.
That contrast, rather than the technology itself, is the substance of the complaint against LG. All of these companies want the same data. What differs is how much work a customer has to do to discover it.
The advertising connection
Gamers Nexus claims LG sends all the data its hardware collects to the ads unit. LG Ads Solutions markets itself with promises of “precision targeting at the device level, across households,” and touts that advertisers can “own the living room” by placing ads on devices inside what it calls “the connected LG household.”
According to the ad division’s fact sheet, there are 49 million LG TVs in the US powered by webOS, with total reach extending to 363 million “addressable secondary devices” — a figure that encompasses other hardware detected on the same networks.
LG’s product pages describe voice features with terms such as “Intelligent Voice Recognition” and “Clear Voice Pro,” but do not highlight that audio transcripts may be generated while the display is in standby. Customers seeking more information must navigate to an “LG Privacy” link located far down lengthy product pages and then sift through multiple policy documents, none of which reference LG Ads Solutions on the main product page.
Responsible disclosure
The research team also documented remote code execution vulnerabilities in webOS that are currently moving through the responsible disclosure process. Burke said the team was working with security researchers to disclose the flaws properly. Because the details are withheld until that process concludes, the severity of the new flaws cannot yet be independently checked.
The platform does have a documented track record to judge that claim against. In November 2023, Romanian security vendor Bitdefender found four vulnerabilities affecting webOS versions 4 through 7 that could be chained to take over a set, and disclosed them publicly in April 2024 after LG shipped patches on 22 March that year.
IdentifierEffectCVE-2023-6317Bypasses the authorization prompt and adds a user profile to the setCVE-2023-6318Escalates that foothold to rootCVE-2023-6319Operating-system command injectionCVE-2023-6320Command injection executed as the dbus user
The service the flaws sat in was designed for local network access only, but a scan at the time found more than 91,000 televisions exposing it directly to the open internet. That is the relevant precedent for the current disclosure: the exposure came less from the bugs themselves than from how many sets were reachable by anyone who went looking.
Given the broad network listeners and data sweeps that operate out of the box, the team’s recommendation was straightforward: disconnect LG sets from the internet entirely and use external streaming devices instead. Short of that, switching off Live Plus and declining the interest-based advertising consent stops ACR data being used for ad targeting, according to the company.
LG responds
LG issued a detailed rebuttal on 9 September, a day after the video went live, calling the tracking and snooping characterisation “not true.” The company said microphone capture is triggered only when a user presses the voice button on the remote or says the wake word after explicitly enabling far-field voice recognition, and that wake-word detection runs on the set itself.
On the central allegation the answer is conditional rather than a flat denial. LG says that when a television “appears to be turned off, it only monitors for the wake word if you have previously enabled the Far-Field feature,” and that where no wake word is detected the audio is processed locally and deleted without reaching company servers. It did not dispute that the sets sweep the local network, describing that as an industry-standard behaviour that enables device pairing, content sharing and smart home functions. Several of the specific findings, including the claim that stored voice files are uploaded once connectivity returns, drew no response. Before the video, the company had told other publications that its TVs do not “collect, record, or store ambient conversations,” and that voice recognition is an optional feature processing voice data only when activated by the user.
Recent history
The new report lands less than two months after Gamers Nexus flagged that certain LG monitors were automatically installing an app through Windows’ device metadata system when connected to an online Windows 11 PC. That app collected device data and displayed pop-up promotions for McAfee. LG said at the time that “McAfee is not installed automatically and is never installed without the user’s explicit consent.”
The public pressure from that video prompted an intervention from Microsoft and ultimately led LG to disable the pop-up ads.
The broader smart TV market has made ACR and similar data-collection technologies commonplace. Research suggests many consumers are willing to trade data for financial savings on hardware, but privacy implications are magnified when the same devices are installed in boardrooms and medical offices.
The source of much consumer frustration, according to critics, is that manufacturers rarely disclose the full extent of data collection at the point of purchase. Generating audio transcripts while a television appears to be off is not something LG highlights in its marketing materials — yet that is precisely what the testing uncovered, according to the investigation.