Security2 publishers2 min readPublished
A Gamers Nexus and Level1Techs teardown shows LG smart TVs surveying the networks they join, which makes the lobby panel and the exec's home-office set part of your asset problem rather than someone's privacy complaint.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
This scanning is part of how the product normally operates, not evidence of exploitation. Among the device classes the rooted sets identified were smartwatches, network switches, printers, 3D printers, servers and HVAC hardware [3], and firmware analysis showed the television could also survey nearby Wi-Fi networks, logging names, signal strength and channel [4]. In an office, that inventory describes a floor rather than a living room.
Where traffic goes is documented separately. One test set connected to numerous LG and advertising endpoints and repeatedly contacted the ACR infrastructure of Alphonso [6], the entity LG's advertising business operates through after LG took a controlling stake in 2021 [17]. Gamers Nexus estimated roughly 4GB of ACR-related data a month from a single television [7]. That is 48GB a year per panel, or 480GB a year from a ten-screen estate of lobby and meeting-room displays [1]. LG Channels requests could also reveal which channel was being watched [20].
Neither Gamers Nexus nor Malwarebytes reports having observed the LAN device inventory itself leaving the set. Malwarebytes describes that data as information that could help build a picture of the devices in a household and, combined with ACR data and advertising IDs, support detailed profiles [8]. So the discovery and the ACR egress are each documented; the link between them is inference at this stage.
The audio findings sit on the other side of the line. After taking control of test units, the researchers recorded through built-in microphones, USB webcams and remote-control microphones [9], and Malwarebytes reports capture continuing when the television appeared to be off [12]. One demonstration pulled the audio of a conference call passing through the television off the television itself [11]. Gamers Nexus frames this as what an attacker inherits after compromise, not as evidence that LG records private conversations [18].
That leaves placement. The researchers involved recommend disconnecting LG smart TVs from networks while the undisclosed vulnerabilities move through responsible disclosure [14], and isolating sets from sensitive home or business systems [21]. Malwarebytes recommends a separate IoT or guest network for televisions and turning UPnP off at the router [15]. For a boardroom panel or an executive's home office, the practical version of that advice is a VLAN the television cannot route out of.
Malwarebytes splits the findings into two categories: some concern LG's intended product behaviour, and others depend on vulnerabilities still under disclosure [19], and the product-behaviour category will still be there once LG fixes the second.
Ranked by verification strength, evidence, and original report placement.
For the investigation, Gamers Nexus partnered with researchers Mr. Bruh, U-Turn, and Wendell from Level1Techs; the team analyzed network traffic with Wireshark, decrypted and decompiled LG firmware, rooted test televisions, and inspected system processes and logs.
During testing the LG TVs repeatedly scanned the local area network and detected dozens of unrelated devices; collected information included device names, MAC addresses, signal strength, internal IP addresses and other attributes.
The tested TVs identified smartphones, PCs, smartwatches, network switches, printers, 3D printers, servers and HVAC-related devices.
Firmware analysis showed that nearby Wi-Fi networks could be detected, including their names, signal strength and channel information.
After gaining control of test units, researchers demonstrated recording through built-in microphones, USB webcams, remote-control microphones and other audio sources.
In one demonstration an LG G5 continued recording locally after its network connection was removed, and the audio was retrieved after connectivity was restored.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific method, single origin
The method reaches print in unusual detail: traffic captured with Wireshark, LG firmware decrypted and decompiled, test sets rooted before anything was demonstrated. What does not reach print is a model list, a firmware version, or one capture a reader could check, and the remote-code-execution findings are deliberately held back. Both write-ups are retellings of the same Gamers Nexus investigation, and LG answers neither of them.
Shipping behaviour, unmeasured spread
The scanning and the Alphonso contacts happened on retail sets in ordinary use, one of them serving mainly as an HDMI monitor, which argues for designed behaviour rather than a lab artefact. Scale is where it thins out: the G5 is the only model named, no firmware version is given, and neither publisher estimates how much of LG's installed base behaves the same way.
Standby headline, post-compromise mechanism
Malwarebytes' headline has attackers listening in standby; the demonstrations behind it begin with an attacker who already controls the set, and CyberInsider says outright that nothing shows LG recording conversations. The finding that needs no compromise at all, a television logging the MAC addresses and internal IPs of everything around it, gets the calmer paragraphs.
Safety advice with a checkout link
Malwarebytes' mitigation list ends in a promotion for its own VPN, and the precedent it cites for ACR scrutiny is its own earlier reporting. LG's interest is plainer still: the advertising infrastructure the sets kept contacting is a subsidiary it controls, so ACR staying switched on is revenue rather than a setting. Neither publisher says how the teardown was funded.
Consistent but uncorroborated
The two accounts do not contradict each other, though agreement between two summaries of one investigation adds little weight. The withheld vulnerability details leave the security findings unverifiable for now, and our own annual traffic arithmetic rests on a single estimate for a single set.
product
A "private and secure" face search left 9 million images in an open bucket4 publishers
invest
Samsung puts the humanoid body and its AI brain under one CTO1 publisher
security
Community maps in MECCHA CHAMELEON could write files anywhere on a player's disk1 publisher
security
Two Artifactory flaws poisoned metadata, not artifacts, and that was enough to break a shared cache1 publisher
Publishers with included, body-backed reporting in this cluster.
1 article · September 7, 2026
1 article · September 7, 2026