Summary
- According to Gamers Nexus, LG TVs are capable of scanning a household's Wi-Fi network and capturing audio through their microphones, even when they appear to be turned off or disconnected from the internet.
- In May, LG reached a settlement with Texas regulators, agreeing to cease the collection of viewing data without obtaining informed consent.
- Additional security research uncovered unaddressed remote-access vulnerabilities and residential-proxy code, which reroutes internet traffic from other users through the buyer's home connection.
What happens when an LG smart TV is not actively being watched? The digital media firm and popular YouTube channel Gamers Nexus invested over 500 hours and approximately $70,000 to uncover the answer, which revealed significantly more than what was advertised.
Collaborating with hardware reviewer Level1Techs and three independent security experts, the team discovered that LG's televisions scan the entire Wi-Fi network of a household using Universal Plug and Play (UPnP), a protocol that allows devices to automatically locate and communicate with one another, thereby mapping all connected devices such as phones and laptops.
In one experiment, they managed to extract clear audio from a TV with a black screen, and again after completely disconnecting it from the internet. This investigation took place after LG had already signed a privacy settlement with Texas regulators.
The majority of the tracking is conducted via Automatic Content Recognition (ACR) software, which samples audio and visual content, converts it into a digital fingerprint, and compares it against a reference database to identify what is being viewed, as noted in a review by Malwarebytes.
Gamers Nexus found that LG's ACR continues to function even when the TV is solely being used as an HDMI monitor for a laptop, indicating that switching inputs does not deactivate the tracking.
Moreover, the TVs are capable of scanning the network to identify all connected devices.
Researchers muted the main microphone through the settings menu, yet they were still able to retrieve a usable recording from a hidden microphone that the mute function does not affect. This raises questions about the effectiveness of the mute feature.
In another test, they left a TV unplugged from Ethernet, spoke near it, and observed that once it reconnected, it uploaded the stored audio, capturing speech from approximately 60 feet away through a wall.
Voice commands are converted into text and stored in on-device logs. The microphone remains active for an additional 10 to 15 seconds after someone stops speaking, allowing it to capture subsequent conversations in the room, regardless of whether anyone is addressing the TV. LG stated in July that its TVs "do not collect, record, or store ambient conversations," but the evidence suggests otherwise.
Interestingly, LG's advertising executives have been candid about the benefits. Several leaders from LG Ad Solutions have stated on camera that the company "owns the glass," emphasizing their strategy to link a household's TV viewing habits to other devices within the home.
According to LG, while consumers purchase the television, the data it collects belongs to the company.
This data is processed through Alphonso Inc., a company in which LG acquired a controlling interest in 2021 and has since faced legal challenges. Serge Matta, the president of global ad sales for LG Ad Solutions, previously led Comscore, which was charged by the SEC in 2019 for inflating revenue by about $50 million. Matta personally incurred a $700,000 penalty, repaid $2.1 million to Comscore, and accepted a 10-year ban from managing a public company.
However, there are no restrictions on private companies.
Security Concerns
Additionally, researchers identified remote-code-execution vulnerabilities, allowing an attacker to execute commands on a TV from a remote location, which LG has not fully resolved. One method tricks the TV's built-in browser into pairing with a deceptive mobile-device pop-up, granting remote access without any physical interaction with the TV. LG has requested that researchers withhold technical details while the disclosure process is ongoing.
A compromised TV can serve as more than just a listening device. Security firm Spur discovered residential-proxy code within about 42% of apps available on LG's webOS store, which reroutes internet traffic from other users through the buyer's home connection, as reported by Krebs on Security. LG's senior vice president, John Taylor, stated that the company is collaborating with developers to eliminate or suspend the apps that contain this code.
LG's television and account agreements exceed 30,000 words combined, which would take an average reader three to four hours to peruse. Shortly after Gamers Nexus released its initial report on LG in July, the company added a forced-arbitration clause to these agreements, preventing buyers from pursuing legal action in court or participating in class-action lawsuits, a notable timing.
In May, Texas Attorney General Ken Paxton announced a settlement that required LG to obtain informed consent before gathering ACR viewing data and to provide users with a clear opt-out option, following a December lawsuit that also named Samsung, Sony, Hisense, and TCL. Gamers Nexus discovered that the Do Not Sell My Personal Information toggle remains disabled by default before a user connects to the internet or agrees to any terms. This raises further privacy concerns.
This appears to be a common issue among tech companies that prioritize convenience over privacy. From Meta's AI glasses recording individuals without consent to numerous users rushing to erase their data from ChatGPT this spring due to privacy violations. Gamers Nexus is currently crowdfunding a follow-up investigation into Samsung, Vizio, and other smart TV manufacturers, while legal actions against Sony, Hisense, and TCL remain active in Texas courts.
