Put a packet capture on a retail LG smart TV and the television starts listing the rest of the house. Testers watched the sets identify phones, PCs, printers, network switches and smart-home hardware on the local network, and log the names and signal strengths of nearby Wi-Fi networks along with device identifiers.
The work comes from a new investigation by Gamers Nexus, carried out with Level1Techs and independent security researchers, which combined packet captures with firmware analysis across several LG models. Malwarebytes summarised the findings in its write-up, and drew the distinction that matters for a reader trying to work out how alarmed to be. Some of what the team documented is the product behaving as designed. Some of it depends on security flaws that are still going through disclosure.
The TV keeps a map of the house
Device discovery on its own is not exotic; plenty of software enumerates a local network. What makes it worth attention is the company it keeps. LG televisions also run Automated Content Recognition, or ACR, which samples what appears on the screen or comes through the speakers, turns it into a digital fingerprint and matches that against a reference database to establish what is being watched. Set a household device inventory beside a viewing log and an advertising identifier and you have a reasonably detailed portrait of a home, assembled by an appliance most people do not think of as a computer at all.
A microphone that works with the screen off
The researchers also demonstrated that a compromised television could capture audio through its microphone, including while the set appeared to be switched off. In one test the TV stored audio locally after it was unplugged from the internet, then sent it on once the connection was restored. They have reported remote code execution vulnerabilities to LG and are withholding the details while responsible disclosure runs its course, so the mechanism is not public and we are not going to guess at it.
Why a television is worth attacking
A compromised TV is a foothold. It sits on the same network as laptops, phones and printers, it is rarely monitored, it is often years behind on firmware, and it has a microphone. That combination makes it a quiet place for an attacker to stand while probing everything else, which is the same reason cheap connected hardware keeps turning up in real cases, from a robot vacuum flaw that exposed home cameras and Wi-Fi passwords to the Android TV boxes conscripted into a botnet.
Turn off ACR and give it its own network
None of this is unique to one brand, and there is no reason to panic about a television. There is reason to treat it as the networked computer it is. Install firmware updates when they appear, and check the model's support page rather than waiting for a prompt. Read the privacy and user-agreement screens instead of accepting them by default, and switch off ACR, viewing-data collection, personalised advertising and voice recognition if you do not use them. Put televisions, speakers and cameras on a guest or IoT network so a compromised one cannot reach a laptop. Turn UPnP off on the router unless something genuinely needs it, and never expose a TV service directly to the internet.
The awkward part is that the most invasive behaviour the team documented is not a bug at all. Malwarebytes notes that a share of it is intended product behaviour, which means the only control a customer gets over it is a settings menu they have to go and find.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.