TL;DR - Gamers Nexus spent a reported US$70,000 and 500+ staff-hours investigating LG smart TVs, and the findings are worse than the headline. Native ACR tracks what you watch down to the HDMI input, the TV scans your whole LAN and inventories every device it finds, researchers demonstrated remote exploitation that turns the set into a covert listening device (including capturing audio from a USB webcam while the microphone kill-switch is off), and twelve days after the first video dropped, LG slipped forced arbitration into its terms. What you need to do: put every smart TV on an isolated VLAN or block list using Wendell's free guide, flip the "do not sell my personal information" toggle that ships disabled, and audit any LG display in your meeting rooms.
By The Numbers
| Figure | What it is |
|---|---|
| 216 million | LG smart TVs in the field, per Gamers Nexus' investigation title |
| 4 GB/month | ACR fingerprint data one test TV sent to LG, mostly text |
| 6.4 GB/month | Estimated total traffic to and from the TV, before accepting any agreements |
| 38 | Other devices on the test LAN the TV discovered and inventoried |
| 75-90 seconds | Fastest telemetry ping interval observed |
| 10-15 seconds | How long the mic stays live after a wake word, logging ambient speech |
| ~70 feet | Distance at which the TV recorded clear, usable audio |
| 12 days | Between GN's first LG video (16 July) and LG's forced-arbitration terms update (28 July) |
I read a lot of security research. Most of it makes me nod, bookmark it, and move on. This one made me put my coffee down.
Gamers Nexus - yes, the hardware review channel - just published a 2 hour 15 minute investigation into LG smart TVs, funded by a US$70,000 backer campaign and executed with three independent researchers: MrBruh, uturn, and Wendell from Level1Techs. It opens with footage of LG Ad Solutions president Serge Matta telling advertisers, on camera, "we own the glass. We own the TV." Not you, even though you paid for it. Them.
Here's why this is a defender story and not just a privacy outrage story: the counter-move already exists. Wendell published an open, free how-to guide for walling an LG TV off from your network, and the CTO at your company (or you, for your home) can ship it in a weekend. The exploit details are under responsible disclosure, so the window to get ahead of this is now, while the attack surface is documented but the weaponisation isn't public.
Let me walk you through what the investigation found, who's running the data pipeline, and exactly what to do about it.
The surveillance pipeline: what your LG smart TV ships home
Automatic content recognition (ACR) is the acronym that matters here. In plain English: the TV takes audio or video fingerprints of whatever is on screen, including anything you plug in over HDMI, and ships those fingerprints home. LG's ACR is first-party, run through a subsidiary called LG Ad Solutions (incorporated as Alphonso Inc., more on them shortly).
The part that got me is the LAN scanning. Per the investigation, the test TV continuously scanned the local network and found at least 38 other devices: a 3D printer, an air purifier, internal servers, smartphones with staff usernames exposed, smartwatches, an editing PC it correctly identified as running TeamViewer, and the thermostats. LG sells air conditioners. As the host noted, they now own a device that pinned the HVAC system, all because someone plugged a television into the network to watch TV.
Then there's what you watch. The TV's built-in "LG Channels" feature fires DNS queries that name the channel in the query itself: a query containing "CNN US" while watching CNN US, "NBCN" while watching NBC News Now. One researcher put it plainly: those DNS requests can be reversed to determine what channel you're watching at any given time, and that's visible to anyone on the LAN, your ISP, and by extension the government.
Volume: roughly 4 GB of ACR fingerprint data per month, predominantly text. That's an enormous amount of text about your household. And opting out is its own trap. The firmware decompile showed that when you opt out, the TV sends one final snapshot of all tracking data to Alphonso on the way out. The "anonymous" X-device-ID beacons that remain are encrypted rather than hashed, which means anyone holding the per-model secret key (including advertisers) can reverse the ID and recover your TV's MAC address. The model secret is stored on the TV's filesystem, so a jailbroken set de-anonymises the whole model line.
Your counter-move: none of this works if the TV can't reach the internet. Segmentation details in the fix section below.
The exploit chain: one "OK" from a root shell
GN worked with the researchers under responsible disclosure, so the vulnerability specifics aren't public yet. What's public is the shape of the exploit chain, and the shape is enough to act on.
The demonstrated chain needs exactly one user interaction: a prompt that says a mobile device would like to pair with your TV, and someone pressing "OK." That's all she wrote: full root shell on the TV. The researchers also found a separate zero-day that appears to connect over the network non-interactively. If your conference room TV sits on public Wi-Fi, someone on that network could exploit it without anyone touching the remote. With physical access and ten minutes alone with the set, they were in and out.
Once inside, the TV is a powerful Linux computer with a remarkable microphone collection. From the shell they could capture audio from:
- The built-in far-field microphone array (voice quality good enough to replace studio mics, per Wendell, and clear at roughly 70 feet, around corners)
- A low-bitrate speaker-feedback mic that still reconstructs speech
- HDMI audio
- Bluetooth devices
- USB peripherals, including a generic webcam
- The LG remote's push-to-talk mic, with the on-screen popup suppressed so the room gets no visual cue
The detail that should end the "just use the kill-switch" argument: the test TV has a physical microphone switch. With the switch in the OFF position, the built-in mic dies but every other audio source stays live. They recorded audio through the USB webcam accessory with the switch off. The menu toggles are equally decorative: the researchers re-enabled every voice recognition feature from the command line after disabling them in the UI.
Then the "ambient conversation" finding. LG's public statement to TechRadar says LG TVs "do not collect, record, or store ambient conversations." In testing, after a wake word, the TV stayed in a listening window for 10 to 15 seconds of continued speech, sometimes minutes, transcribing everything said in the room to a plaintext log on the set. Two crew members had a work conversation behind the TV without knowing it was listening. It logged them. The log files live on a RAM disk that survives standby; you have to physically pull the power to clear them. And the TV keeps recording with the network cable unplugged, storing audio locally in its 16 GB of flash until connectivity returns and someone copies it off.
Run the boardroom scenario: wall-mounted LG display, appears off, an attacker with the pairing-prompt chain exfiltrates recordings of the ambient conversation in the room.
"Fancy Bear would be very comfortable inside LGTV." - one of the researchers, on the TV as a pivot point for lateral movement
Your counter-move: an exploited TV with no network route is a tape recorder with no courier. Isolation breaks the exfiltration path even if the exploit lands.
Who's behind the curtain: Alphonso, LG Ad Solutions, and an SEC-banned president
LG's smart TV agreement names Alphonso, Inc. as the service partner collecting and using viewing information for ads. LG acquired a controlling stake in Alphonso in 2021, and Alphonso rebranded as LG Ad Solutions. The two have been locked in lawsuits since, with AdExchanger reporting Alphonso filed four suits against its controlling entity after what it described as a 2022 "boardroom coup." Billions of dollars are at stake, which tells you exactly how much your viewing data is worth.
Now the president. Two years before becoming LG Ad Solutions' president of global ad sales, the SEC charged Serge Matta and Comscore (the company he was CEO of) with a fraudulent scheme to overstate revenue by approximately US$50 million. Matta settled in 2019, paid a US$700,000 penalty, reimbursed Comscore US$2.1 million, and accepted a 10-year bar on serving as an officer or director of a public company.
LG Ad Solutions is private. The SEC bar doesn't apply. The vendor harvesting your household's data is led by someone the SEC explicitly removed from public-company oversight, and the regulatory loop around him is structurally weaker than anything you've audited before.
Two more data points. LG Ad Solutions built a product called Loop IQ with Affinity Solutions that ties ad exposure on your TV to actual credit card transactions, in Matta's own words tying "the actual CTV exposure to a merchant, and to an actual purchase." And the sales materials pitch political campaigns on reaching "voters that matter." This isn't a privacy team with an ads problem. It's an ads company with a television division.
Microsoft's quiet role: Nuance processes the voice data
Buried in LG's smart TV legal agreements: Nuance Communications is named as the service partner that "collects and analyzes voice data" when you use voice commands. Microsoft bought Nuance for US$19.7 billion in 2021 (completed 2022). Microsoft and LG go back decades: Windows phones, Android patent licensing, autonomous vehicles, Xbox apps in cars, and a reported multi-billion-dollar deal for LG data-centre cooling.
I flag this because of the McAfee sidequest. After users found LG's monitor installer (which auto-installed via Windows Update without consent) pushing McAfee, Microsoft publicly threw LG under the bus and a Microsoft VP confirmed LG disabled the McAfee popup. That statement said nothing about Nuance. When you read LG's voice-capture terms, the data processor on the other end is a Microsoft subsidiary. Both companies know exactly what's in those agreements. Only one of them took the PR hit.
The corporate defence: forced arbitration, 12 days later
GN posted its first LG investigation on 16 July 2026. On 28 July, LG updated its smart TV terms of use. The new language requires US customers to resolve disputes through "binding and final arbitration" with limited exceptions, on top of a pre-existing class-action waiver. Some LG TVs carry a fine-print "forced arbitration notice" sticker on the back, applied at the factory, discoverable after you've unboxed and wall-mounted the thing. And when GN bought an LG smart monitor during production, it announced out of the box that new terms (arbitration agreement, AI-based service terms) would take effect in 30 days on 26 August 2026, pre-accepted unless you acted.
The structural read: LG is heading off expensive, public class actions before they become public record, while continuing to change the terms whenever it likes. Arbitration keeps disputes private, kills precedent, and pairs with the class waiver to make individual claims uneconomical. Your counter-move here is boring but real: check whether your jurisdiction honours these clauses (in Australia, consumer guarantees under ACL can't be contracted away, and the OAIC takes privacy complaints), and factor "vendor litigates its own customers" into procurement.
The defender counter-move: Wendell's lg-tv-block-mini-how-to
The canonical defensive response is free and already written. Wendell of Level1Techs published LG TV Block Mini How-To on the Level1 forums, walking through exactly how to wall an LG TV off from the rest of your network. If you can edit a firewall rule or a blocklist, you can ship this. A competent admin can do a fleet of meeting-room TVs in a weekend, and that is not hyperbole: the guide is a checklist, not a research project.
If you read one thing after this post, make it the guide. And if you want the broader frame for why "corporate surveillance plus individual vulnerability is the new attack surface," pair it with my piece on the TeamPCP arrests. TeamPCP got arrested for doing covertly what LG does openly, at 216-million-unit scale, with a president the SEC banned from public companies. Same primitive, different licence to operate.
What you can do today
- Isolate every smart TV. Follow Wendell's guide: dedicated VLAN or strict egress blocklist for TV MACs. For home users who won't touch a firewall, the crude version works: unplug the TV from the network and use a streaming box you control. (Caveat from the investigation: some ISP routers broadcast open neighbourhood Wi-Fi that devices auto-join, so check for that.)
- Flip the buried toggles. "Do not sell my personal information" ships disabled, before you even connect to the internet. Enable it, disable ACR in the deep menus, and accept that the TV experience degrades when you do. On Wendell's older set, "limit ad tracking" was off by default despite never accepting terms.
- Audit the fleet. Any LG display in meeting rooms, waiting rooms, or customer-facing spaces is now a documented listening-post candidate. Treat it like you'd treat an unpatched edge device: segment it or remove it. This is a permissions audit, and permissions audits are boring and essential.
- Read what you bought. Check your LG purchase for the arbitration sticker and class-action waiver, and decide whether that vendor relationship still makes sense for your organisation.
- Complain where it counts. US readers: the FTC takes complaints at reportfraud.ftc.gov. Australian readers: the OAIC handles privacy complaints, and the ACCC is actively interested in dark patterns. ACR running against your stated preferences is exactly the kind of complaint that builds a case file.
Key Takeaways
- "We own the glass" is a policy, not a gaffe. LG Ad Solutions' president said it on camera, and the telemetry (LAN scans, HDMI ACR, channel-naming DNS queries) backs it up.
- Opting out is theatre. The TV sends a final full snapshot to Alphonso when you opt out, and the "anonymous" device ID is reversible to your MAC address with the per-model key.
- One "OK" on a pairing prompt yields root. With a non-interactive zero-day also found, network isolation is the control that holds even after the exploits go public.
- The mic kill-switch only kills one mic. Webcam, remote, HDMI, Bluetooth and feedback mics all stay capturable, and menu toggles are re-writable from a shell.
- The data pipeline is run by an SEC-banned executive leading a private subsidiary the ban doesn't reach, with ads tied to credit-card transactions.
- Forced arbitration arrived 12 days after the first video. LG is defending the business model, not the customer.
- The fix costs a weekend. Wendell's block guide plus a buried-toggle pass covers home and fleet.
Frequently Asked Questions
Is my LG TV actually spying on me? If it's connected to the internet and you've accepted (or accidentally accepted) the terms, GN's testing shows it collecting viewing fingerprints, scanning your network for devices, and beaconing home. Without accepted terms it still contacted advertising endpoints and scanned the LAN in their samples. The capability is documented; the conservative assumption is that it's running.
Are the vulnerabilities public? Has LG patched them? No, and not that anyone has confirmed. GN withheld exploit details under responsible disclosure, and notes LG didn't respond to the concerns they sent. That's your window: isolate the TVs now, before weaponisation is public.
Does unplugging the ethernet cable stop it? Mostly, with two caveats. Some ISP routers broadcast open neighbourhood Wi-Fi that devices can auto-join, and the TV keeps recording audio locally while offline, exfiltrating when connectivity returns. Physical isolation plus a network block is the robust version.
Does the microphone kill-switch make it safe? No. The mechanical switch kills the built-in mic only. GN captured audio from a USB webcam with the switch off, and re-enabled voice features from a shell after they were disabled in the menu.
Do other TV brands do this? GN plans to test Samsung, Vizio and others in follow-ups, funding permitting. Vizio paid US$2.2 million to settle FTC charges over exactly this kind of ACR tracking back in 2017, so LG is not the category's first offender, just the best-documented current one.
Is any of this illegal in Australia? Unclear, and that's the problem. The Privacy Act's APPs and Australian Consumer Law (dark patterns, consumer guarantees) are the relevant hooks, and the OAIC and ACCC both take complaints. Forced arbitration clauses face a much colder reception under ACL than under US law.
My Take
The line I keep coming back to is "we own the glass." I paid for my TV. You paid for yours. The idea that the vendor retains ownership of the screen in your living room (and by extension the room itself, and by extension the credit card you used at Target afterwards) is the most honest thing ad-tech has ever said out loud. Usually this stuff is buried in a 40,000-word terms document. This time they said it on camera.
The comforting part is that the defence is genuinely cheap. This is not a "wait for the patch" problem or a "buy new hardware" problem. It's a segmentation problem, and segmentation is the bread and butter of everyone reading this blog. If a consumer TV can map a security researcher's lab in an afternoon, imagine what the one in your boardroom has already inventoried.
And to the CTOs: your auditors will eventually ask whether the displays in your meeting rooms were assessed like any other networked device with a microphone. "We watched a YouTube video and VLAN'd them that weekend" is a much better answer than silence.
Further Reading
- Gamers Nexus: "216,000,000 Spy TVs | The LG Smart TV Problem" - the primary investigation (2h15m, worth every minute)
- Wendell's LG TV Block Mini How-To - the canonical defensive counter-move
- The Steam avatar that unmasked TeamPCP - the companion frame: surveillance plus vulnerability equals attack surface
- AI Offense Is Now Automated. Your Defense Isn't. - the editorial pattern this post follows: offense documented, defense still manual
- Your router is a security risk (fix it in 10 minutes) - the home-network segmentation starter
- Your Copilot rollout is a security disaster - another "vendor ships surveillance by default" audit
- LG's US privacy policy - read what "share for targeted advertising purposes" commits you to
- FTC fraud reporting and the OAIC - where complaints actually land
Audit note (sources): Primary investigative source is Gamers Nexus' video of 6 September 2026 (youtu.be/6IFVTcM28KA), transcript-verified; specific claims attributed to GN, researchers MrBruh, uturn and Wendell, and LG Ad Solutions' published materials and executive statements as quoted therein. The defender counter-move is Wendell's Level1Techs guide. SEC settlement figures are as quoted in the investigation (SEC v. Comscore and Serge Matta, 2019). Exploit details remain under responsible disclosure; this post describes only what GN made public. LG had not responded to GN's concerns at publication.
Mathew Clark Founder, SecureInSeconds Currently: checking which VLAN the TV ended up on, because apparently it checked first.



