Smart TV privacy: LG not alone - most smart TVs track users

Gamers Nexus and Level1Techs tested LG smart TVs and found routine ACR tracking and, after rooting a set, potential audio/video recording and extended microphone capture. Some claims require root access and remain unproven on unmodified TVs.

Smart TV privacy: LG not alone - most smart TVs track users
Reading time: 3 Minutes
Follow on Google

Gamers Nexus and Level1Techs tested LG smart TVs and documented wide-ranging data collection and, after gaining root access via a vulnerability, the potential to record audio and video when the set appeared to be off.

Smart TVs from multiple manufacturers commonly track viewing behavior and share those data with partners. Many sets use automatic content recognition, ACR, which fingerprints audio or video from internal apps or external inputs and matches it to databases for recommendations and targeted advertising. Companies such as Nielsen also use similar data to measure cross-platform viewing.

Consent for data collection is usually requested during setup, but researchers say those notices can be buried in long agreements or nudged by interface design. In the LG test Gamers Nexus showed the TV presenting six separate agreements, one for ACR, with the default selection on "select all" while only two agreements were required to finish setup.

Gamers Nexus and Level1Techs then rooted an LG TV using a vulnerability to probe further behavior. After rooting, they observed the TV could record audio and video while apparently off and that information about the local network was transmitted to LG servers. Those findings apply to the rooted device as tested.

Researchers also tested the microphone. When voice search was active the TV continued recording for roughly 10 to 15 seconds after the last detected speech. By enabling far-field microphone mode and increasing sensitivity they received the wake phrase "Hi LG" and other sounds at greater distances.

Under those conditions, speech that continued after activation could be captured as part of a voice search. The microphone tests used deliberate sensitivity increases and an optional wake-word feature to extend range.

Security researchers note an attacker would typically need access to the user’s private network to exploit a vulnerability that permits rooting. Gamers Nexus' Steve Burke suggested a TV might switch networks to exfiltrate data if ethernet were disconnected, but the video presented no evidence that LG TVs in the wild actually do so; that claim remains speculative.

Users concerned about privacy can accept only the agreements necessary for basic operation and disable advertising and tracking options in the TV settings. Use a separate email for the TV account and review privacy menus, because option names vary across models.

For voice control, disable the TV microphone or use an external streaming device with its own assistant. Turning off Wi-Fi and unplugging ethernet will reduce network activity and effectively make the set a non-smart display; streaming can then run through a separate device. Some streamers, such as Apple TV 4K, do not use ACR, though Apple still collects usage data for personalized recommendations and streaming apps log user activity.

Not all claims in the Gamers Nexus video are equally documented. Several potentially alarming behaviors were observed only after researchers rooted the device, and some scenarios remain conjectural rather than demonstrated on unmodified sets.

Emma Collins

“I cover emerging technologies, digital innovation, and the intersection of tech and everyday life. My goal is to make complex trends accessible and inspiring.”

Leave a Comment

Comments (1)

datapulse

So wait, they got root access first? Are these TVs actually spying out of the box or only when someone's hacked?? Feels unclear