Millions of LG smart televisions running the webOS operating system can be turned into covert listening devices that continue recording even when the set appears to be switched off or disconnected from the internet, according to a detailed technical investigation published this week.
How the vulnerability works
The research, conducted by the YouTube channel Gamers Nexus with assistance from Level1Techs and independent security analysts, began with an analysis of network traffic generated by LG OLED models. They found that webOS televisions actively scan the local network, silently cataloguing smartphones, connected objects, internal IP addresses and mapping surrounding Wi‑Fi networks by name and signal strength. While such discovery behaviour is common for devices that support casting or smart‑home integration, the researchers identified critical vulnerabilities in the implementation that allow an attacker on the same local network to take control of the television.
Once compromised, the television functions as a hidden microphone. The team demonstrated that audio capture remains possible while the device is in standby mode, a state most users would assume disables all sensors. The findings were presented in a two-hour video that walks through the network enumeration, the exploit chain and the subsequent persistence mechanisms.
Offline recording and delayed upload
Perhaps the most striking element is the behaviour when the television is completely cut off from the internet. The researchers showed that a compromised set continues to capture ambient sound in the room and writes the recordings to local storage. When an internet connection is restored, whether by the user reconnecting Wi‑Fi or the television automatically re‑associating with a known network, the stored audio is transmitted to external destinations. This means that simply unplugging the Ethernet cable or turning off the router does not stop the surveillance; it only delays the exfiltration.
The implication is that an attacker who gains a foothold on a home network, perhaps through a vulnerable router, a compromised IoT device or a phished credential, can plant a persistent listening post that survives network outages and reboots. The television's always‑on standby power supply, designed for quick start and voice‑assistant readiness, provides the necessary energy for continuous audio capture.
The role of automatic content recognition
The vulnerability sits alongside LG's automatic content recognition (ACR) system, which uses visual and audio fingerprints to identify what the viewer is watching. The vast majority of that data feeds LG's advertising ecosystem, building profiles for targeted marketing. The researchers note that the same microphone and processing pipeline used for ACR is what the exploit hijacks. LG's settings menus offer very limited options to disable ACR, leaving consumers with what the investigators describe as "few escape routes" from the data collection.
Additional vulnerabilities discovered during the audit could potentially allow remote code execution, expanding the threat from passive eavesdropping to full device control. The researchers have not released the full technical details of the exploit chain, following a responsible disclosure timeline intended to give LG a window to develop and distribute firmware patches.
Disclosure timeline and LG's response
As of publication, LG Electronics has not issued a public security advisory or a timeline for fixes. The company's typical patch cycle for webOS involves monthly firmware updates, but critical vulnerabilities of this severity often warrant an out‑of‑band release. The research team says it shared its findings with LG prior to the video's publication and is withholding proof‑of‑concept code to reduce the risk of immediate weaponisation.
The absence of a coordinated vulnerability disclosure (CVD) programme for consumer electronics remains a structural weakness. Unlike enterprise software vendors, most TV manufacturers do not operate public bug‑bounty platforms or publish security advisories in a standardised format. This opacity makes it difficult for users to know whether their specific model is affected or when a fix will arrive.
Regulatory context in Europe
The findings arrive as the European Union's Cyber Resilience Act enters its implementation phase, imposing mandatory security requirements for connected devices placed on the single market. The regulation, which covers products with digital elements, requires manufacturers to handle vulnerabilities responsibly, provide security updates for a defined period and disclose incidents to national authorities. LG's televisions, sold in vast numbers across the EU, fall squarely within scope. The General Data Protection Regulation also applies: audio recordings of identifiable individuals constitute personal data, and any processing without a lawful basis, especially covert recording, would breach multiple articles.
National data‑protection authorities in France, Germany and Ireland have previously fined smart‑TV makers for opaque ACR practices. The French CNIL, for instance, has investigated automatic content recognition on connected televisions and issued guidance requiring explicit consent. The current vulnerability, which bypasses user controls entirely, would likely attract regulatory scrutiny if LG cannot demonstrate prompt remediation.
What owners can do now
Until a firmware patch is available, the only reliable mitigation is to disconnect the television from the local network entirely, both Wi‑Fi and Ethernet. That, however, disables smart features, streaming apps and software updates, effectively turning a smart TV into a dumb display. Some users may isolate the TV on a separate VLAN or a guest network with no access to other devices, which limits the attack surface but does not eliminate the offline recording capability if the TV is already compromised.
Disabling ACR in the settings menu reduces the data LG collects for advertising but does not address the underlying vulnerability. The microphone remains active for voice‑assistant functions, and the researchers' exploit does not depend on ACR being enabled. Physical microphone switches or hardware disconnects are not present on current LG models.
Organisations
LG Electronics · Gamers Nexus · Level1Techs