LG accused of 'egregious invasion of privacy' over TV data collection
- ID
- 22372
- Status
- summarized
- Published
- 08 Sep 2026, 10:15 PM
- Fetched
- 08 Sep 2026, 10:15 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/08/lg-accused-of-egregious-invasion-of-privacy-over-tv-data-collection/5294956
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 5.5
- Created
- 08 Sep 2026, 10:18 PM
- Tags
- Audience
- developerssaas_startup_founders
What happened
Gamers Nexus researchers found LG smart TVs continued capturing audio after voice recognition activation, including in standby mode, and stored plaintext transcripts locally. Wireshark analysis revealed the TVs also enumerated unpaired devices on the local network (smartphones, routers, BMCs, PCs) and collected nearby Wi-Fi network names, signal strengths, IP addresses, and location data. An alleged remote code execution flaw is being disclosed to security researchers, and the TVs reportedly can store captured audio offline and transmit it once reconnected.
Why it matters
If you build or deploy IoT devices on networks where LG smart TVs are present, the TVs' local network enumeration and alleged RCE vulnerability are a concrete attack-surface concern worth network segmentation. For anyone shipping connected hardware, this is a cautionary case study in how aggressive telemetry and ad-tech integration can become a reputational and legal liability.
Discussion angle
What does responsible telemetry look like for connected devices, and at what point does data collection for 'ad personalization' cross into something builders should architect against on their own networks?