LG TV shown scanning LAN for third-party phones and other devices
LG OLED TVs, including the high-end G5 model, were found to actively scan local networks for other devices even when appearing to be turned off, discovering dozens of unconnected devices like phones and smartwatches The TVs can identify IP addresses, geographic location, Wi-Fi network names, signal strengths, and internal IP addresses of other devices on the network as native functionality, not requiring any vulnerabilities LG TVs were also shown to record microphone audio in plaintext while unp
Analysis
TL;DR
- LG OLED TVs, including the high-end G5 model, were found to actively scan local networks for other devices even when appearing to be turned off, discovering dozens of unconnected devices like phones and smartwatches
- The TVs can identify IP addresses, geographic location, Wi-Fi network names, signal strengths, and internal IP addresses of other devices on the network as native functionality, not requiring any vulnerabilities
- LG TVs were also shown to record microphone audio in plaintext while unplugged from the network, with data potentially transmitted to LG upon reconnection
- LG claims audio monitoring only occurs when Far-Field voice functionality is explicitly enabled and a wake word is detected, with local processing and deletion of non-matching audio
- The findings raise broader privacy concerns for all smart TVs, especially given ISP dual SSID setups that can cause devices to autoconnect to open neighborhood networks
Why It Matters
This investigation reveals that premium smart TVs can function as covert surveillance devices on a home network, collecting detailed metadata about every connected device and potentially ambient audio even when users believe the TV is off. For AI and IoT practitioners, it underscores the critical importance of transparent data collection practices and the risks of assuming device disconnection equates to privacy.
Technical Details
- Researchers from Gamers Nexus and Level1Techs used Wireshark packet captures and firmware inspection on the LG OLED65G3PUA ($2,500 MSRP) to demonstrate LAN scanning behavior that identified dozens of devices without any explicit connection
- The TV's native functionality includes collecting IP addresses, geographic location, SSID names, Wi-Fi signal strengths, channel numbers of neighboring networks, and internal IP addresses of all devices on the local network
- Microphone audio was captured in plaintext storage even when the TV was physically unplugged from the network, raising concerns about delayed data exfiltration upon reconnection
- LG's Far-Field wake word feature was identified as the mechanism for audio capture, with the company stating audio is processed locally and deleted unless a wake word like "Hi LG" is detected
- The investigation also noted ongoing remote code execution vulnerabilities currently in disclosure process for LG TVs
Industry Insight
- Smart TV manufacturers must reconsider default privacy configurations, as the assumption that an "off" device is inert is dangerously incorrect and erodes consumer trust across the IoT ecosystem
- The dual SSID problem highlighted by ISPs (e.g., Comcast Xfinity, AT&T hotspots) means smart TVs may autoconnect to neighbor networks, expanding the attack surface beyond the user's private network—industry standards for explicit opt-in on network changes are needed
- This case reinforces the growing regulatory and consumer pressure on ad-supported device models; companies relying on addressable device data (LG claims 363 million addressable secondary devices in the US) should proactively adopt privacy-by-design principles before legislation catches up
Disclaimer: The above content is generated by AI and is for reference only.