Security analysis reveals LG smart TVs run ad software that monitors nearby connected devices and contains vulnerabilities allowing hackers to access built-in microphones. Gamers Nexus published detailed findings on the privacy and security threats.
A comprehensive security analysis by Gamers Nexus has identified serious privacy and security issues in LG smart TVs, highlighting risks that extend beyond typical smart device concerns.
The investigation found that LG's advertising software uses automatic content recognition (ACR) technology to track nearby connected devices. This tracking occurs independently of user awareness or explicit consent, collecting data about what devices are in proximity to the TV.
Security Vulnerabilities
Beyond device tracking, researchers discovered security flaws that could allow unauthorized access to the TV's built-in microphone. These vulnerabilities create a potential eavesdropping vector, enabling attackers to remotely listen through the device without user knowledge.
The combination of tracking capabilities and microphone vulnerabilities presents a multi-layered privacy threat. Users may unknowingly have their device ecosystem monitored while simultaneously exposing themselves to remote audio surveillance.
Broader Implications
The findings underscore ongoing concerns about data collection practices in smart home devices. Manufacturers frequently embed tracking and monitoring capabilities into consumer electronics, often burying disclosure in lengthy terms of service agreements.
LG's implementation demonstrates how advertising technology can intersect with security design to create compounding risks. The automatic content recognition system operates as first-party software, meaning it runs directly on the TV rather than through external services, making it a native part of the device's infrastructure.
Gamers Nexus conducted the analysis as part of its broader "Data Dragnet" series examining data collection and privacy practices in consumer technology.
The findings raise questions about whether current regulatory frameworks adequately address security vulnerabilities in connected devices, particularly those with built-in microphones and tracking capabilities. Consumers should review their LG TV settings and consider disabling data collection features where options are available.
Over 36,000 Plex Media servers remain exposed online without security patches, leaving them vulnerable to active exploits. The unpatched systems pose a significant risk to user data and network integrity.
An Ohio man received a 15-year prison sentence for using AI-generated sexually explicit videos to extort and cyberstalk multiple women. The case marks a significant legal action against deepfake-based sexual exploitation.
A security researcher has disclosed a critical zero-day vulnerability in Microsoft Defender dubbed 'ShieldCrash' that grants attackers SYSTEM-level access. The exploit was released publicly following Microsoft's September 2026 Patch Tuesday updates.
A critical window exists to address fundamental security vulnerabilities across systems before widespread exploitation becomes inevitable. Industry experts warn that delayed action could expose infrastructure to coordinated attacks.