Back to news
Cybersecurity Alert
September 16, 2026 by EmailMeNow IT Consulting

Researchers Say Compromised LG TVs Can Listen in Standby

Gamers Nexus and Level1Techs say a compromised LG OLED can capture mic audio in standby. LG disputes ambient recording. Audits (ideal 100%): malwarebytes.com 71%, lgads.tv 44%, lg.com 42%, gamersnexus.net 41%.

Source: Malwarebytes · LG Electronics · Gamers Nexus

NewsPrivacyIoTPhishingMFAYubiKeyAuthenticator AppsCybersecurity
Dark living room with a standby OLED television showing a small red LED and a microphone icon on the bezel

Malwarebytes (September 7, 2026; updated September 10) recaps a Gamers Nexus investigation with Level1Techs and independent researchers. The team tested retail LG OLED sets running webOS, including a 2025 G5 and an OLED65G3PUA. They describe three overlapping problems: native network discovery, Automatic Content Recognition (ACR) viewing telemetry, and security bugs that they say raise the cost of a compromise.

This is not an LG “was breached” story. It is a product-privacy and firmware fight. LG’s September 12 newsroom statement says uncompromised TVs do not continuously record conversations. Malwarebytes’ own update says the researchers’ audio demo involved a compromised set.

We scanned lg.com, lgads.tv, malwarebytes.com, and gamersnexus.net. 100% is the ideal overall domain-security score. None reach it.

Dark living room with a standby OLED television showing a small red LED and a microphone icon on the bezel

Snapshot

FieldDetail
InvestigationGamers Nexus + Level1Techs + researchers · video Sept 6–7, 2026
MalwarebytesSept 7 write-up; Sept 10 LG-response update
LG replyNewsroom Sept 12 — disputes ambient recording
Models named in press2025 G5 OLED; OLED65G3PUA (Ars)
RCEReported to LG; still in responsible disclosure — no public CVE we found
CourtListener0 matching RECAP privacy-class dockets after Sept 1, 2026

What researchers showed versus what LG says

Keep these lanes separate. Mixing them is how a “spy TV” headline outruns the evidence.

Native behavior (packet captures / firmware, as reported): tested sets scanned the LAN for phones, PCs, printers, switches, and other smart-home gear. They also collected nearby Wi-Fi names, signal data, and device identifiers. Ars Technica quotes Steve Burke: the G5 “crawled our entire network” and found devices belonging to staff who were not part of the test. Burke said that path did not require a vulnerability. ACR then fingerprints what is on the glass — including HDMI and other inputs, not only LG apps.

Compromise path (researchers, as reported): a compromised TV could capture microphone audio while the display looked off, keep capturing after the Ethernet cable was pulled, and retrieve stored audio once the network returned. Malwarebytes and Ars both stress that offline-cache claim. Press also describes plaintext speech-to-text logs and recording windows that lasted 10–15 seconds after a voice command. We are not linking exploit write-ups or proof-of-concept code.

LG’s reply (company statement): TVs do not continuously record or transmit conversations. Speech-to-text starts only after the remote mic button or a user-enabled wake word such as “Hi LG.” Wake-word audio is processed on the device and discarded if no wake word matches. Far-field / hands-free listening in standby happens only if that feature was turned on. Voice sessions are capped (LG cites ~10 seconds of silence or ~18 seconds max). LG says voice data is not stored for later upload when the TV is offline. ACR is opt-in, uses audio fingerprints from the internal audio processor (not the mic), and does not store voice recordings or screenshots. LAN scanning, LG says, is a standard smart-TV connectivity function — not household advertising profiles. Nearby Wi-Fi / signal data is a separate function that may support approximate location when ACR agreements are accepted.

LG confirmed that TVs do scan local networks. It has not published a CVE-by-CVE answer to the reported remote-code-execution bugs. Those remain in disclosure.

LG Ad Solutions markets 216 million global LG smart TVs and 49 million U.S. sets. That installed base is advertising scale, not a count of compromised devices.

LG says ACR, voice recognition, and interest-based ads are optional and off by default. LG USA support tells owners to review choices under Settings → Privacy & Terms → User Agreements. Terms of Use and Privacy Policy are required for smart apps such as Netflix and YouTube. Viewing Information, Voice Information, and personalized-ad agreements are not.

The same help page says LG updated its Terms of Use — mainly the Arbitration Agreement — with the new terms effective August 28, 2026. That is a contract change, not a firmware fix. Decline the optional boxes if you did not mean to turn on ACR or far-field voice.

On supported models, LG documents a hardware microphone switch. When that switch is off, the TV mic no longer feeds hands-free recognition. The remote mic still works only if voice recognition is enabled and you press the button.

Do not treat “I use it as a dumb HDMI monitor” as a privacy off-switch. Researchers said some of the behavior they captured still applied when the set was used that way.

Laptop showing a generic firmware-update email beside a handwritten card that says to type the official support URL

What to do

  1. Type lg.com/us/support yourself and install webOS updates from the TV’s software-update menu. A “critical TV firmware” email or SMS is hostile until that official path says so.
  2. Open Settings → Privacy & Terms → User Agreements. Uncheck Viewing Information (ACR), Voice Information, and interest-based / cross-device ads unless you want them. Turn off Live Plus / far-field / “Hi LG” if you do not use voice.
  3. Use the hardware mic switch when the model has one. Covering a pinhole is not a substitute for a documented mute.
  4. Put TVs, cameras, and speakers on a guest / IoT VLAN. Disable UPnP on the router unless you have a reason to keep it. Hotel and clinic waiting-room TVs are the same class of device — they sit on networks that also carry guest or staff traffic.
  5. Report suspected identity theft at IC3.

A hardware key on your LG account does not patch webOS. It does cut follow-on takeover if a fake “LG support” page harvests the same password you reuse.

MFA: YubiKey and Google Authenticator

A living-room TV does not need the owner’s second factor to sample HDMI audio. The MyLG / ThinQ login still matters for app stores, warranties, and support phishing. Grades match our MFA directory.

GradeMeaning
FailSMS, voice, or email OTP — or no public MFA path
PassSelf-serve Google Authenticator-style open TOTP
StrongFIDO2 / YubiKey-class security key for sign-in
PlatformGradeYubiKeyAuthenticator
LG ThinQ / MyLGFailNoNo
Malwarebytes AccountFailNoNo

LG USA ThinQ help is email + password, plus email verification at signup. Quick logins via Google / Facebook / Amazon are those providers’ MFA, not an LG security-key path. We found no YubiKey or Google Authenticator enrollment page for MyLG.

Malwarebytes Account help (updated December 9, 2025) sends a verification code to email on every sign-in. Email OTP is Fail. Third-party pages that claim authenticator-app or SMS 2FA are not the official article.

Directory: MFA support directory · Business Apps (LG) · Email & Identity (Malwarebytes).

Use these on mailboxes and accounts that actually document them — not as a webOS patch.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
Proton PassPasskeys + authenticator-style TOTPProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key and phone authenticator beside a password-only email login

Independent cybersecurity audits

We audited LG, LG Ad Solutions, Malwarebytes, and Gamers Nexus hosts on September 16, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not score webOS firmware or whether a given TV’s mic is muted.

OrganizationDomainOverallvs 100%
Malwarebytesmalwarebytes.com71%−29
LG Ad Solutionslgads.tv44%−56
LGlg.com42%−58
Gamers Nexusgamersnexus.net41%−59
DomainIdentityTransportWebsite
malwarebytes.com90%45%43%
lgads.tv25%15%43%
lg.com25%15%37%
gamersnexus.net20%15%40%

Audit links: lg.com · lgads.tv · malwarebytes.com · gamersnexus.net

lg.com at 42% is −58 from the ideal. Transport 15% on three of four rows is a mail-transport gap — not a reason to trust a “webOS emergency update” message. Malwarebytes at 71% is the strongest of this set and still misses 100%.

Four padlocks stop short of a complete finish line, illustrating domain audits that miss the ideal score

Illustration only — scores are in the tables above, not in the artwork.

Website stack note

Passive website-tech probes on September 16, 2026:

DomainStack signal
lg.comNext.js; DigiCert TLS expires 2027-03-26
lgads.tvStack undetected; DigiCert TLS expires 2027-02-08; HTTP→HTTPS redirect not confirmed
malwarebytes.comWordPress (version hidden); Amazon Trust TLS expires 2027-03-19
gamersnexus.netDrupal 11 (probe: older than 11.4.7); Let’s Encrypt TLS expires 2026-11-01

Point-in-time only. A marketing CMS version is not a webOS finding. lgads.tv without a confirmed HTTPS redirect is a site note, not proof about living-room mics.

Blacklist, lookalikes, CourtListener

Email blacklist checks (public DoH, September 16, 2026): lg.com, lgads.tv, malwarebytes.com, and gamersnexus.net were clear on mail/domain lists we can query. lg.com showed an informational SPFBL note on a web/CDN IP. That is not mail reputation. Do not lead as “LG is blacklisted.”

DNS lookalike scans (BEC profile, registered signals only):

Brand scannedTo reviewLikely ownedBEC staging
lg.com4911
malwarebytes.com1960
lgads.tv310
gamersnexus.net211

lg.com is a two-letter brand, so many registered hits are unrelated (alg.com, 1g.com). The phishing-relevant names are the support/secure affixes and staging hosts:

LookalikeTechniqueNote
lg.apptld-swapBEC staging (NS + MX)
lg-support.comaffixRegistered — not LG USA support
lg-secure.comaffixRegistered — not LG
gamersnexus.orgtld-swapBEC staging (NS + MX)
igads.tvhomoglyphRegistered — not LG Ad Solutions

lge.com and lgads.com looked brand-owned (overlap / redirect). Type lg.com/us/support and lg.com/us/newsroom/corporate/statement-understanding-privacy-on-lg-smart-tvs yourself. Continuous monitoring: Cybersquat Domain Monitoring.

CourtListener

RECAP search September 16, 2026: 0 dockets matching “LG Electronics U.S.A” + privacy class filed after September 1, 2026. Older LG federal rows in the same window are mostly patent and product-liability noise. A coverage or class-action filing can still appear later. It is not on the docket today.


Run a free audit at audit.emailmenow.com or contact EmailMeNow for IoT VLAN design, vendor-access MFA, and phishing-resistant sign-in aimed at the 100% ideal.


Sources: Malwarebytes (Sept 7; update Sept 10) · LG newsroom (Sept 12) · LG user-agreements help · LG ThinQ login help · Gamers Nexus video · Ars Technica · The Verge · LG Ad Solutions · Malwarebytes Account 2FA. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 16, 2026. Domain scores: audit.emailmenow.com only. Researcher claims about compromised-TV audio are not a finding that uncompromised sets continuously record. No exploit samples.