This post is also available in:
Smart TVs increasingly behave less like traditional televisions and more like connected computers. That brings streaming services and voice controls into the living room, but it also creates privacy and security questions about what information the television can collect from both its users and the network around it.
An investigation by Gamers Nexus and independent cybersecurity researchers has found that LG smart TVs running webOS can scan local networks, track viewing activity and store text generated from voice commands. The researchers stress that much of the behavior they observed appeared to be built-in functionality rather than exploitation of a security vulnerability.
Using the network-analysis tool Wireshark, the team monitored traffic generated by retail televisions. In one experiment, a TV identified 38 devices on the same network, including smartphones, smartwatches, a 3D printer, an air purifier and other connected hardware, even though those devices had not been paired with the television.
According to Cyber News, the researchers reported that the TVs could collect information including internal IP addresses and details about nearby Wi-Fi networks. Such network information can potentially help infer a device’s location.
Another major component is Automatic Content Recognition (ACR). This technology identifies material appearing on the screen or playing through the television, allowing viewing behavior across different inputs to be analyzed. The company publicly markets ACR-derived audience insights and says its footprint covers 216 million smart TVs worldwide.
During testing, one television reportedly transmitted roughly 4GB of ACR-related data per month.
Voice functionality raised separate concerns. The researchers found that speech used during voice interactions could be converted into plain text and stored in local logs. In one test, data continued accumulating while the television was offline and was subsequently uploaded after connectivity returned.
The investigation does not establish that the company’s televisions continuously record ambient conversations. The company has publicly stated that its TVs do not collect, record or store ambient conversations. The researchers’ findings specifically concern voice-command interactions, although they reported that the microphone could remain active for roughly 10 to 15 seconds afterward and that audio could also be captured while a television appeared to be in standby.
The team separately identified potential remote-code-execution vulnerabilities in webOS, but technical details are being withheld during responsible disclosure. If exploitable, such vulnerabilities could raise more serious security concerns because software control of a microphone-equipped television could potentially turn it into a surveillance device.
That issue has particular relevance beyond private homes. Smart TVs are also installed in hotels, hospitals, offices and meeting rooms, sometimes sharing networks with sensitive equipment or sitting near confidential conversations. For government, defense and corporate environments, connected displays therefore need to be treated as networked endpoints rather than passive screens.
The investigation highlights a broader challenge surrounding consumer IoT devices: the television may be hanging on the wall, but from a cybersecurity perspective, it is another computer, with sensors, network access and data collection capabilities that deserve the same scrutiny as any other connected device.

























