216,000,000 Spy TVs | The LG Smart TV Problem
Gamers Nexus released a detailed investigation into LG smart TVs. Working with Level1Techs and independent security researchers, the team spent hundreds of hours and significant resources testing retail LG OLED models, including the G5.
They found that LG’s first-party Automatic Content Recognition (ACR) continuously samples on-screen video and audio, converts it into fingerprints, and sends the data to LG Ad Solutions servers. LG executives have stated on camera that the company “owns the glass,” knows who is in the household, identifies secondary devices, and extends reach to mobile. The investigation captured network traffic showing the TVs scanning local networks for unrelated devices (phones, smartwatches, etc.), recording nearby Wi-Fi network names and signal strengths, IP addresses, and location-related data.
Researchers demonstrated that microphones could capture clear ambient audio and produce plain-text transcripts even when the screen appeared off. In some tests, recording continued after the TV was disconnected from the network; the audio was stored locally and later uploaded when connectivity returned. Additional vulnerabilities, including potential remote code execution paths, were identified and are in the responsible-disclosure process. The team recommends isolating or disconnecting LG smart TVs from networks.
LG Ad Solutions markets access to roughly 216 million smart TVs worldwide and claims reach to hundreds of millions of secondary devices. The investigation argues that data monetization through targeted advertising and profiling has become a major revenue driver, sometimes exceeding hardware margins. Consent flows and dark patterns were also criticized.
LG later denied claims of continuous ambient listening or spying, stating that voice data is processed only when the user activates the feature via the remote button or an enabled wake word such as “Hi LG,” with local processing and deletion if no wake word is detected. The company confirmed network-device discovery for connectivity features and said ACR and interest-based advertising require separate opt-in. Security researchers and the original investigation maintain that the observed native behavior and vulnerabilities raise serious privacy concerns.

