Gamers Nexus, Level1Techs, and independent researchers reported that LG smart TVs may capture microphone audio while in hibernation or apparently off, including audio not preceded by a recognized wake word. Testing and firmware inspection allegedly found recordings retained locally in plaintext even while the television was disconnected from the internet. The researchers also said the sets collect local-device IP addresses, nearby Wi-Fi SSIDs and signal strengths, and location-related information, creating privacy and security risks if retained data is later exposed or transmitted.
LG denied that its televisions continuously record conversations, stating that voice processing begins only when users press the remote voice button or enable the Hi LG wake word. The company said wake-word detection occurs locally and unrecognized audio is immediately deleted, while describing network-device discovery as a standard capability supporting connectivity, content sharing, and smart-home features. LG added that voice recognition, Automatic Content Recognition, and interest-based advertising are separately opt-in and can be disabled.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
LG denied that its televisions continuously record conversations, stating that voice processing occurs only after a remote voice-button press or an enabled “Hi LG” wake word, with unrecognized wake-word audio immediately deleted. LG also said device discovery supports connectivity features and that voice recognition, Automatic Content Recognition, and interest-based advertising require separate opt-in consent and can be disabled.
Gamers Nexus, Level1Techs, and independent security researchers reported from network-traffic testing and firmware inspection that LG smart TVs collect local-device and nearby Wi-Fi data, and may capture and locally retain microphone audio, including while disconnected from the network or in hibernation mode.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.