That expensive OLED you bought for its picture quality reportedly has a second job. Packet captures and bench tests by Gamers Nexus, working alongside Level1Techs and independent security researchers, have demonstrated that LG smart TVs — including the flagship G5 running webOS — can record audio in standby, map every device on your home network, and route data to LG’s advertising infrastructure. This isn’t a conspiracy theory. It’s Wireshark logs.
Your TV Is Running Network Reconnaissance
When the screen goes dark, LG’s webOS reportedly begins cataloguing every device on your network.
When the screen goes dark, the device reportedly starts mapping your phone, your partner’s smartwatch, your kid’s laptop — hardware that has nothing to do with watching television. Gamers Nexus investigator Steve Burke documented exactly this: the TV “crawled our entire network and found dozens of unrelated devices, including smartwatches and phones of our staff who didn’t even know we were working on this.”
The TVs also harvest neighboring Wi-Fi network names and signal strengths — classic location-profiling behavior. Every sweep feeds LG Ad Solutions, LG’s targeted advertising division, which claims reach to 363 million secondary addressable devices in the US alone. That figure, sourced from LG Ad Solutions’ own marketing, reveals what the network scanning is actually for. LG’s Automatic Content Recognition (ACR) also fingerprints on-screen audio and video across every input — including HDMI — so even your Apple TV viewing gets logged. LG has issued no public response to the investigation’s findings.
The Screen Is Off. The Microphone Isn’t.
Standby mode, it turns out, is a setting — not a promise.
To you, standby means the TV is sleeping. To the TV, standby apparently means the microphone stays active. Bench tests confirmed the built-in mic can record audio in standby with the screen dark under test conditions. Disconnect the Ethernet cable and it doesn’t necessarily stop — the TV reportedly buffers recordings locally and uploads them the moment connectivity returns. Offline isn’t full protection. It’s a delay. Audio capture can also extend to compatible soundbars and external mics inside the LG ecosystem, expanding the potential surface considerably.
Then there’s the security layer, which makes everything worse. webOS carries documented remote code execution (RCE) vulnerabilities — CVE-2024-1885 in LG Signage webOS and CVE-2018-17173 in LG SuperSign EZ CMS — with newly discovered zero-days currently in responsible disclosure. An attacker on your network could potentially:
- Control microphone features
- Pivot across your LAN
- Access stored recordings
That’s a risk scenario, not a confirmed widespread attack pattern — but documented RCE vulnerabilities sitting alongside demonstrated data-collection capabilities is exactly the kind of combination that keeps security researchers up at night.
What To Actually Do About It
Settings toggles won’t get you far — physical disconnection is the only mitigation with real teeth.
The researchers’ recommendation is blunt: disconnect your LG TV from the internet entirely and run an external streaming stick — Roku, Fire TV, Apple TV — through HDMI instead. Disabling ACR or voice assistants in the settings menu is not a reliable fix; the data collection reportedly runs deeper than those toggles reach. Physical disconnection remains the most effective mitigation available right now.
Regulators will eventually catch up. Off-state recording and aggressive LAN scanning without meaningful consent will draw scrutiny under existing privacy frameworks. Whether that pressure forces the broader industry to clean up its practices is the open question — because LG may be aggressive here, but it isn’t alone.





























