Independent researchers have found that after voice control is activated, LG TVs may keep "listening" for another 10-15 seconds and convert the captured speech into text logs stored on the device. During testing, the system accidentally recorded and transcribed a conversation between two members of the research team who were unaware the experiment was still running.
According to cybersecurity experts, the problem is that voice data can remain on the TV itself in text form — meaning that if the device is hacked, an attacker doesn't just get an audio recording, but a ready-made, easily readable transcript of conversations happening inside the home. In effect, an ordinary device for watching content turns into a potential source of leaked personal and sensitive family information.
The research effort was extensive: according to published data, the team spent roughly $70,000 (nearly 1.5 million CZK) and more than 500 hours on it. Specialists tested production LG TVs, analyzing their network traffic and software.
The scandal initially broke over microphone tests: in a separate experiment, researchers gained control of a TV and demonstrated that the device could pick up sound even when the screen appeared to be off or the TV was in standby mode.
A test conducted without an internet connection proved particularly telling: after being disconnected from the network, the TV continued to store recorded data locally, and once reconnected to the internet, that data became accessible again. It's worth noting this involved a device that had been hacked — it doesn't prove that all LG TVs record ambient sound while switched off under normal conditions.
Researchers also discovered that the TV can scan the home network and identify other connected devices. In one test, according to published findings, the system detected 38 such devices — including phones, smartwatches, a printer, a thermostat, and other networked equipment.
Particular attention was drawn to Automatic Content Recognition (ACR) technology, which creates a digital "fingerprint" of whatever is being watched, allowing the TV to identify exactly what's on screen. According to the researchers, this means a smart TV can collect data not only about the content being viewed but also about other devices on the same network.
The specialists passed all their findings to LG so the company could prepare updates and fix the vulnerabilities. Until patches are released, the researchers are withholding further details to avoid handing hackers a blueprint for an attack — which means it's currently impossible to fully verify all the claims.
LG TV owners are advised to keep an eye on firmware updates and privacy settings, and to consider disabling unused features such as ACR, personalized advertising, viewing data collection, and voice recognition.
LG has rejected the investigation's conclusions. "The claims made in the recently published video do not reflect reality," said Kristina Haliková, PR manager for LG in the Czech Republic and Slovakia.
According to her, LG TVs only process voice data when a user presses and holds the microphone button on the remote, or when, after the Far-Field voice recognition feature is activated, the system detects a wake word such as "Hi LG." Outside of these situations, the devices do not collect or record conversations around them: if the wake word isn't detected, no voice data is sent to any server, and the audio processing used to detect the wake word happens locally, with the data deleted immediately afterward.
The feature that searches for and connects to other devices on the same network, the LG representative said, is necessary for smart TV functionality and is standard for this type of device and other smart-home equipment. ACR technology, Haliková added, operates strictly on an opt-in basis for personalizing content and ad recommendations — if consent isn't given, ACR data is not used for advertising purposes.
Source: novinky.cz