A new investigation has claimed that LG smart TVs can be used to eavesdrop on users’ conversations, including when the TVs appear to be turned off or are disconnected from the internet.
A report by Gamers Nexus, conducted in partnership with Level1Techs and independent security researchers, examined retail LG internet-connected TVs to determine what information they collect through their Automatic Content Recognition (ACR) systems.
ACR technology is now common in smart TVs and is typically enabled by default. It collects information about what people watch and other data that can be used for targeted advertising.
The investigation claimed LG TVs can continuously collect information about their owners and nearby devices, with some data potentially being captured even when the TV appears to be switched off or is disconnected from the network.
Researchers said the TVs were collecting information about nearby devices on Wi-Fi networks, recording audio through their microphones, and using audio and video samples to identify what was being watched.
‘Spy TVs’
The more than two-hour video, titled ‘216,000,000 Spy TVs’, warned smart TVs “can pry into your personal life with greater precision than you might realise”.
Researchers claimed the TVs could continue listening to conversations around them while switched off or apparently in standby mode.
“LG TVs are able to be utilised as eavesdropping listening devices, in part due to the advertising functionality that is built into them,” the report said.
The researchers demonstrated that a compromised TV could record and store audio locally while disconnected from the network, before transmitting those recordings when reconnected.
The investigation also found that LG’s ACR system can collect information including a user’s location, IP address, the names of nearby Wi-Fi networks and the names of devices connected to the same network.
The researchers suggested this could help explain a discrepancy between LG’s claim of having almost 216 million TVs globally and its access to data from 363 million secondary devices.
This is an “egregious invasion of privacy”, the researchers said.
‘We own the glass’
The investigation cited previous statements by LG executives saying they “own the living room”, and that they “own the glass [and] the TV”.
“We know who is in the LG households, we know which devices are there,” one LG executive was quoted as saying.
LG sells TV data through its advertising business, LG Ad Solutions, which describes its platform as the “future of TV advertising”.
The platform allows advertisers to target audiences based on content viewership, specific TV types, purchase habits of users, viewing habits and their location.
The security researchers also identified several “concerning vulnerabilities” in LG TVs, which they said were being handled through the responsible disclosure process.
One was a remote code execution vulnerability that could allow an attacker to take control of aspects of a TV’s operation.
The researchers also demonstrated how a vulnerability could be exploited to gain access to the TV’s network and retrieve recordings made by the device.
The report said users could disable the relevant ACR functionality by going to Settings > General > System > Advanced Settings > Live Plus.
LG did not respond to a request for comment.
The findings come after growing scrutiny of smart devices and their ability to collect information from users’ homes.
Early last year, Apple agreed to pay $US95 million to settle a lawsuit alleging its smartphones had been eavesdropping on users through its Siri voice assistant.
The legal action centred on accidental activations of Siri where the user said something other than the phrase “hey Siri”, and claimed confidential recordings were passed on to third parties without consent.