Tech Myth Thursday 009: Your Smart TV Is Just a Screen—What the LG Privacy Controversy Reveals
Quick answer
A smart TV is not merely a display. It is an internet-connected computer with an operating system, applications, advertising services, device-discovery features and, on some models, microphones or voice controls. The recent LG controversy raises legitimate privacy and security questions, but it does not prove that every LG television was hacked or that every owner's private information was stolen.
The careful conclusion is this: researchers reported concerning behavior on the televisions they tested; LG disputes important parts of their interpretation; some data-processing capabilities are acknowledged by LG; and owners can reduce their exposure today without waiting for every disagreement to be resolved.
What happened in the LG smart TV controversy?
On September 6, 2026, Gamers Nexus published an investigation produced with Level1Techs and independent security researchers. According to the investigation, tested retail LG OLED televisions collected or created records related to viewing activity, devices on the local network and voice or audio features. The investigators also raised questions about activity when a television appeared inactive or lacked an internet connection.
Those are reported findings from a limited set of tested televisions—not proof that all LG televisions behave identically. Features can differ by model, webOS version, region, user agreement and enabled setting.
LG rejected the characterization that its televisions indiscriminately record ambient conversations. In a statement reported by Tom's Hardware, LG said voice data is processed only when the voice button is held or when an enabled far-field voice feature recognizes a wake word. LG said unsuccessful wake-word audio is processed locally, deleted immediately and not transmitted to its servers.
LG did confirm that its televisions may scan the local network to find compatible devices. It described that as a normal smart-device function. LG also said Automatic Content Recognition, or ACR, is offered through optional consent for personalized recommendations, services and advertising. Tom's Hardware noted that it had not independently verified the investigation or LG's counterclaims.
That disagreement matters. A responsible explanation should say “researchers reported” and “LG says” where the evidence is disputed, rather than turning an unresolved technical argument into a claim that millions of televisions were definitively hacked.
What is Automatic Content Recognition?
Automatic Content Recognition is technology that attempts to identify what is playing on a television. Depending on its implementation and the user's permissions, it may analyze small samples or identifying characteristics of audio or video and compare them with a reference database. This can support recommendations, audience measurement and targeted advertising.
ACR is important because it may recognize content from more than a built-in streaming application. LG's own 2022 announcement said it was rolling out proprietary ACR technology across LG televisions to help advertisers understand television-ad exposure in households. The broader privacy question is not simply whether the TV knows which app is open, but whether it can infer what appears on the screen or plays through connected sources.
ACR does not automatically mean someone is watching a live video feed from your living room. It also does not prove that an attacker has taken control of the television. It is a data-collection mechanism, and the privacy impact depends on what is sampled, how it is linked to a device or household, whether consent is meaningful, where the data travels, how long it is retained and who can access it.
Was this a hack, a breach or a privacy dispute?
These terms are not interchangeable.
A privacy controversy concerns what data a product is designed to collect, how consent works and whether customers understand the trade. A vulnerability is a technical weakness that could permit unauthorized access. A compromise occurs when someone actually exploits a weakness or otherwise gains unauthorized control. A data breach means protected information was accessed or disclosed without authorization.
The current controversy combines claims about intended telemetry and smart features with claims about security weaknesses. That does not establish that every television was remotely compromised or that a database of LG customer records was stolen.
There is relevant history. In 2024, Bitdefender disclosed vulnerabilities affecting webOS versions 4 through 7 that could allow authorization bypass, privilege escalation and command execution under certain conditions. LG issued patches in March 2024. That research demonstrates why television software updates matter, but it should not be misrepresented as proof of a new 2026 mass breach.
What information or capabilities could be involved?
The answer depends on the model, software, enabled features and permissions. Potentially relevant categories include:
Viewing activity. ACR or related services may identify programs, advertisements or other content being displayed. This can be used for recommendations, measurement or advertising profiles.
Advertising identifiers. A television may use a device or advertising identifier to associate activity with a particular device or household without necessarily using the owner's name in every record.
Voice interactions. A microphone-equipped remote or television may process voice commands. The central dispute is whether any voice-related data was created outside the limited circumstances LG describes.
Local-network information. Device discovery can reveal that compatible phones, computers, speakers or smart-home products are present on the same network. Discovery alone is not the same as reading the contents of those devices, but it expands what the television can observe about its environment.
Account and application activity. Smart services may process login state, application use, searches, purchases or preferences. The current reporting does not establish that LG account passwords, banking information or personal files were broadly stolen.
Television control. If a genuine software vulnerability were successfully exploited, an attacker might be able to control television functions, run unauthorized commands or use the TV as a foothold on the home network. That is a risk scenario, not proof that it happened to a particular owner.
Can an LG TV listen when the screen is off?
A dark screen is not always a fully powered-down device. Many smart televisions retain limited standby functions so they can respond to a remote, wake word, casting request, scheduled task or software update. Whether a particular microphone or service continues processing in standby depends on the hardware and settings.
The 2026 investigation reported voice-related activity under conditions the investigators considered inactive. LG says its televisions do not collect or record ambient conversations outside an activated voice-button request or an enabled wake-word feature. Until the technical disagreement is independently reproduced and resolved, owners should not treat either the most alarming headline or a blanket reassurance as the entire answer.
What LG TV owners can do now
1. Install the latest webOS update
Open Settings, select All Settings, then Support and Software Update on many recent models. Choose Check for Updates and enable automatic updates if that matches your preference. Older models may place the option under General or About This TV. LG's support instructions note that menu paths vary by model.
Updates are the first defense against known software vulnerabilities. Privacy-setting changes do not patch exploitable code.
2. Review optional user agreements
On supported models, open Settings, then Privacy & Terms, then User Agreements. LG's September 2026 support guidance says agreements involving viewing information, voice features and personalized advertisements are optional and are not required for basic smart services. Deselect the optional processing you do not want.
Read each agreement rather than choosing “agree to all.” Recheck the selections after a major software update, factory reset or account change.
3. Turn off voice features you do not use
Disable far-field voice recognition, wake-word detection, voice information or related AI voice features if you never use them. Menu names vary. Remember that a microphone may be located in the remote, the television or both, depending on the model.
4. Limit viewing-data collection and personalized advertising
Look for settings or agreements referring to Viewing Information, Live Plus, ACR, personalized recommendations, advertising personalization or interest-based ads. Turning these off may reduce personalization or recommendations, but it should not prevent the television from functioning as a basic display.
5. Separate smart devices from sensitive equipment
If your router supports a guest or isolated IoT network, place the television and other smart-home devices there. The goal is to prevent those devices from initiating connections to personal computers, work laptops, storage drives, printers or security equipment. A guest network helps only if the router actually isolates clients from the main network, so check the router's documentation.
6. Disconnect the TV from the internet if you do not need smart features
A television can often serve as a display for an antenna, game console, cable box or external streaming device without maintaining its own internet connection. This reduces the TV's direct telemetry and remote attack surface, although the external streaming device will have its own privacy and security settings.
7. Remove unused apps and protect the associated account
Delete applications you no longer use, sign out of abandoned services, use a unique LG account password and enable multifactor authentication when the account offers it. These steps reduce unnecessary access paths, but they do not replace firmware updates or privacy controls.
What does not fully solve the problem?
A VPN does not stop a television from processing information locally or discovering devices on the home network. It may change the apparent internet address, but the television can still communicate through the VPN connection.
DNS blocking or a filtering device may reduce connections to known telemetry domains, but it can also break applications, recommendations, updates or sign-in functions. It is an advanced control—not a substitute for patches, consent choices or network isolation.
Covering a microphone opening may reduce sound reaching that microphone, but microphone placement varies and physical modification can damage the television or remote. Disabling unwanted features and disconnecting power are more dependable choices. If you need certainty that the television is not operating in standby, unplugging it or switching off its power at a controllable outlet is different from merely turning the screen dark.
Frequently asked questions
Are all LG smart TVs spying on their owners?
That conclusion is not supported by the available evidence. Researchers reported concerning behavior on tested models, while LG disputes major allegations. Model, region, software version, settings and consent choices all matter.
Did hackers steal information from LG TV owners?
The reporting discussed here does not establish a mass theft of LG passwords, financial information or personal files. It focuses primarily on data collection, device behavior and possible security weaknesses.
Should I immediately throw away my LG TV?
No. Start by updating it, reviewing optional agreements, disabling features you do not use and isolating it from sensitive devices. If you do not want the TV connected, use it as a display with networking disabled.
Does turning off ACR stop every kind of data collection?
No. It can limit content-recognition activity, but applications, streaming services, account systems, crash reporting and essential network functions may process other data under separate settings and policies.
Is a factory reset enough?
A factory reset may erase local settings and accounts, but it does not patch old firmware by itself. It can also present the user agreements again, so carefully review the options during setup.
The practical takeaway
The myth is that a smart TV is only a screen. The reality is that it is a connected computer placed in one of the most private rooms in the home. That does not make every television malicious or compromised, but it does justify the same habits used with phones and computers: install updates, minimize permissions, disable unused features, separate untrusted devices and understand what remains connected in standby.
The LG controversy is still developing. The best response is neither panic nor dismissal. Separate verified capabilities from disputed claims, then use the controls already available to reduce the data and network access you do not need.
Sources
Gamers Nexus investigation: https://www.youtube.com/watch?v=6IFVTcM28KA
LG response reported by Tom's Hardware: https://www.tomshardware.com/tech-industry/big-tech/lg-strongly-denies-tv-security-claims-says-tracking-and-snooping-concerns-not-true-online-investigation-claims-216-000-000-spy-tvs-record-audio
LG guidance on optional user agreements: https://www.lg.com/us/support/help-library/seeing-a-user-agreements-screen-on-your-lg-tv-CT10000018-20155426555618
LG firmware-update guidance: https://www.lg.com/us/support/help-library/lg-tv-how-can-i-update-the-tv-software--20154863567532
LG announcement about ACR: https://www.lg.com/global/newsroom/news/media-entertainment-solution/lg-smart-tvs-get-a-new-acr-solution-legacy-technology-replaced-by-lg-ads-solutions/
Bitdefender webOS vulnerability research: https://www.bitdefender.com/en-us/blog/labs/vulnerabilities-identified-in-lg-webos
Next week: Wi-Fi and Internet Are the Same Thing