Special thanks to Matt Metras, EA, for bringing this to my attention.
A hardware review channel on YouTube spent roughly 500 hours and about $70,000 taking apart televisions, and the result should probably change how you think about every appliance in your house that has a power cord and an opinion.
On September 6, Gamers Nexus published a 135-minute investigation into LG smart TVs, conducted with Wendell Wilson of Level1Techs and independent security researchers MrBruh and uturn. They bought retail sets, including the flagship G5 OLED. They watched the network traffic with Wireshark. They decrypted and decompiled firmware, rooted the televisions, and read the logs.
What they found is not a story about one bad company. It is a story about a bargain most of us accepted without ever being asked.
Let’s dig into what they actually found, because the headlines are compressing three very different problems into one scary sentence.
The television was mapping the house
The researchers found the tested LG sets repeatedly sweeping the local network and identifying other hardware on it. In one test, a single television inventoried at least 38 other devices, including smartphones belonging to staff who had no idea the test was running, plus smartwatches, printers, a 3D printer, thermostats, and HVAC equipment.
Firmware analysis also showed the sets picking up nearby Wi-Fi networks, including names, signal strength, and channel.
None of those devices were ever connected to the television. They were simply nearby.
Now, before anyone with a security background objects: device discovery on a local network is ordinary. Protocols like UPnP exist precisely so your phone can find your printer. Discovery by itself is not an incident.
What is unusual is the scope, the persistence, and the apparent purpose. This is not a television looking for a speaker to pair with.
I bought a display. Apparently I also bought something that keeps a running census of my house.
Automatic Content Recognition does not care which input you use
Automatic Content Recognition, or ACR, is the advertising technology at the center of this. It samples what is on the screen, turns it into a fingerprint, and matches that fingerprint against a reference database to identify the content.
The important part, the part most people get wrong: ACR keeps working when the television is being used as a plain HDMI monitor. Switching inputs does not switch it off. Gamers Nexus estimated one test set exchanged roughly 4GB of ACR-related data per month.
So if you run a laptop into an LG panel, the fingerprinting engine is still sampling. One physician who reviewed the findings reportedly asked the researchers the obvious follow-up question: what does that mean for a hospital display carrying a telemedicine session?
Hold onto that question. We are coming back to it.
The microphone finding, stated carefully
This is where accuracy matters more than outrage.
Researchers demonstrated intelligible microphone audio being captured while the television’s display appeared to be off in standby. They also found that disconnecting the set from the internet did not necessarily stop it. The television kept writing data locally and transmitted it once connectivity returned. Voice interactions were converted to plain text and stored in logs on the device itself.
Separately, they reported security vulnerabilities that would let a compromised television be used as a listening device. Those specifics are being withheld under responsible disclosure, which is exactly how it should be handled.
Here is the nuance that makes this a better story than “your TV is spying on you.” Gamers Nexus did not claim LG ships always-on eavesdropping. Cybernews noted that the findings relate to voice command handling rather than ambient background conversation, and that the researchers’ recommendation was practical rather than apocalyptic: disconnect the television and use an external streaming box.
Note the distinction, because it matters in the next section. “The television is off” and “the display is off” are not the same statement.
Texas had already challenged this
Here is the part I did not expect: Texas had already been litigating this.
On December 15, 2025, Texas Attorney General Ken Paxton sued five television manufacturers (Samsung, LG, Sony, Hisense, and TCL), alleging they used ACR to collect viewing data without consumers’ knowledge or meaningful consent. The complaints sought penalties under the Texas Deceptive Trade Practices Act of up to $10,000 per violation, and potentially up to $250,000 per violation for qualifying violations involving consumers age 65 or older.
Samsung reached an agreement on February 26, 2026. LG’s agreement was announced on May 11, 2026.
Under the LG agreement, the company will not use ACR to collect viewing data without informed consent, must display a pop-up disclosure explaining how viewing data may be collected and used, and must give consumers a clear way to opt out. The Attorney General’s announcement describes behavioral requirements rather than a monetary penalty, and LG admitted no liability. Cases against Sony, Hisense, and TCL remained pending.
Four months after that announcement, Gamers Nexus reported that in its testing, the “Do Not Sell My Personal Information” setting was still off by default, before a buyer had connected to the internet or agreed to anything.
A settlement changed what the company must disclose. It did not change what the device is capable of doing.
That gap, between a legal remedy and an engineering reality, is the whole ballgame.
LG’s denial answers a narrower question
Now put LG’s public statement against that backdrop.
In July, responding to earlier controversy, LG said its televisions do not collect, record, or store “ambient conversations,” and described voice recognition as an optional, user-initiated feature.
Read that sentence again and notice what it does not say.
It does not say the microphone is inactive in standby. It does not say the listening window closes the instant a request ends. It does not address local storage, or network scanning, or ACR sampling of an HDMI input. The denial is doing a lot of work, but mostly by answering a narrower question than the one being asked.
That is not a lie. It is a carefully bounded true statement, which is a different thing, and anyone who has read a privacy policy for a living recognizes the technique immediately.
Meanwhile, the same investigation surfaced footage of LG Ad Solutions president Serge Matta telling an audience, “We own the glass. We own the TV.”
Whatever he meant by it, it is a clarifying sentence. LG Ad Solutions puts its footprint at roughly 216 million smart TVs worldwide. At that scale, advertising is not an incidental feature bolted onto the television business. It is part of the business model, and the hardware is how you reach the audience.
Why this is a professional problem, not just a consumer one
Now back to that physician’s question, translated into our wonderful world of tax.
If you are a tax professional, you are a “financial institution” under the Gramm-Leach-Bliley Act, and the FTC Safeguards Rule requires you to maintain a written information security program. IRS Publication 4557 walks through the same expectations for practitioners.
The rule focuses on identifying and assessing risks to client information. A competent risk assessment has to account for the devices and information systems on your network: what is connected, what it can access, and what it can transmit.
Pull up your WISP and look at what you listed. Is the television on it? I know it isn’t. I know you’re rolling your eyes at me.
I am fairly confident yours covers workstations, laptops, phones, the network printer, maybe the router. I am equally confident it does not mention the television in the room where you take client calls.
That television, per this investigation, may be enumerating devices on the same network your practice management system lives on. It has a microphone. Its content-recognition system can keep sampling the display even when the display is being fed by an external computer.
To be clear about where the evidence stops: the investigation did not establish that LG was reading the contents of documents on screen. ACR fingerprints content to match it against a reference database, and your client’s Form 1040 is not in that database. But from a security standpoint, the fact that a content-recognition system tied to advertising can analyze an HDMI-fed screen at all is worth considering in your risk assessment.
And the operating system underneath it is a Linux derivative whose long-term security depends entirely on the manufacturer continuing to support it. LG’s webOS Re:New program promises four webOS upgrades over five years on covered models, with eligibility varying by model and year. That is a real commitment, and it is more than some competitors offer. It is also quite possibly less time than the panel will remain hanging on your wall.
We spend real money on endpoint protection and multi-factor authentication, and then we put an unmanaged, ad-funded, internet-connected computer with a microphone in the room where we discuss collection alternatives with people in the worst month of their financial lives.
What to actually do
None of this requires paranoia. It requires about twenty minutes.
Turn off ACR. On LG sets, the ACR feature runs under Live Plus: Settings > General > System > Advanced Settings > Live Plus. Turn it off. While you are there, decline personalized advertising and turn off voice features you do not use.
Install firmware updates. Vulnerability findings are only useful if the patch reaches the device.
Take the television off your main network. The cleanest version: do not connect the panel itself to Wi-Fi or Ethernet at all. Use an external streaming box instead. I like Apple TV. That does not eliminate tracking or data collection, but it removes the television’s operating system from your trusted network and lets the panel be a panel.
If you will not disconnect it, segment it. Most modern routers support a guest network or a separate VLAN. Put every IoT device on it. The television can talk to the internet without talking to the machine holding your client files.
Some will argue that you should have an entirely separate internet connection for work and home. That is cleaner, but most people working from home are not going to pay for a second broadband connection. If you’ve ever been in my cybersecurity or WISP class, you know I will say that security is a spectrum.
Then put it in your risk assessment. Not because a regulator will ask about your television. Because the exercise of writing down every device that can hear, see, or enumerate your office is the entire point of having a plan.
The bigger question nobody asked
We have spent twenty years making appliances “smart” without ever stopping to ask whether they needed to be computers.
The refrigerator. The doorbell. The thermostat. The light bulbs. The vacuum. Every one of them arrives with an operating system, network access, cloud services, telemetry, an authentication scheme, and sometimes a microphone or a camera. Which means every one of them also arrives with software vulnerabilities, a privacy policy, an eventual end-of-support date, an advertising incentive, and a company whose economic interests are not identical to yours.
Nobody sat us down and offered that trade. It arrived as a default, and defaults are the most powerful thing in technology precisely because we so rarely examine them. We tolerate an astonishing amount of accumulated complexity, not because we evaluated it and decided it was worth it, but because reconsidering the default never made it to the top of the list.
This one is worth moving up the list. An LG OLED is a genuinely spectacular piece of glass. Let it be glass.
Sometimes the smartest thing you can do with a smart appliance is make it stupid again.
Later this month, I will be teaching a cybersecurity workshop for NATP.
Sources
Cybernews, “Are 200 million LG TVs listening in, even when switched off?”
CyberInsider, “LG Smart TVs found scanning home networks for nearby devices”
Malwarebytes Labs, “LG TV flaws could let attackers listen in, even in standby mode”
The Verge, “LG TVs caught spying even when offline or on standby”
All About Cookies, “LG Smart TVs Caught Listening With the Screen Off”
Office of the Texas Attorney General, LG settlement announcement, May 2026
Fordham Center on Law and Information Policy, “Your Smart TV May Be Watching You Back”




