Researchers from Gamers Nexus, Level1Techs, and independent teams allege that tested LG OLED televisions—including a retail 2025 G5—conducted local-network device discovery, collected nearby Wi-Fi identifiers, and processed microphone audio while appearing to be in standby. They reported that speech-derived logs and audio could be retained locally while the TV was offline, then uploaded after connectivity returned, reportedly to infrastructure associated with LG Ad Solutions. The investigation also found LG’s Automatic Content Recognition (ACR) operating across inputs, including HDMI, raising privacy concerns for home, healthcare, and corporate deployments.
The researchers further disclosed alleged, unpatched remote-code-execution vulnerabilities in webOS network-facing services to LG and demonstrated a controlled proof of concept, though no CVEs or public fixes were cited and responsible disclosure remains in progress. A successful compromise could turn a TV into an audio-surveillance endpoint and provide an attacker a foothold on the surrounding network. LG had not publicly responded to the specific findings at publication; the allegations conflict with its existing statement that its TVs do not collect, record, or store ambient conversations. Organizations should apply available firmware updates, disable unnecessary privacy and UPnP features, and isolate TVs on an IoT or guest network.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The researchers reported undisclosed remote-code-execution vulnerabilities in webOS network-facing services to LG while responsible disclosure was ongoing. They demonstrated a controlled compromise of an LG G5 that recorded audio while the display appeared off and exfiltrated it after connectivity returned; no CVEs, public exploit details, or patches were cited.
In July 2026, Gamers Nexus, Level1Techs, and independent researchers published testing of retail LG OLED TVs, including the G5. They alleged default local-network device discovery, nearby Wi-Fi metadata collection, standby-mode microphone capture and on-device transcription, and later upload of data retained while offline; they also reported ACR activity across inputs including HDMI.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcemalwarebytes.com
Open sourcethecybersecguru.com
Open sourceyoutube.com
Open sourcenotebookcheck.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.