HeadlinesBriefing favicon HeadlinesBriefing.com

GamersNexus Exposes LG Smart TV Security Flaws

Hacker News •
×

GamersNexus released a two-hour investigation into LG smart TVs running WebOS, alleging significant security and privacy vulnerabilities. The video highlights logs showing voice search queries — including test phrases like "My credit card information" and "My Social Security Number is 1 1 1 1 1 1" — stored locally on the device. While the TV is not continuously recording, these logs persist alongside search history.

More concerning claims include the TV's ability to access microphone and webcam while appearing off, operate microphone without network connectivity, and scan the local network via mDNS and SSDP protocols to discover devices like TP-Link Kasa and LIFX smart bulbs, phones, and internal IP addresses. Security researchers Mr Bruh, U-Turn, and Wendell from Level1Techs analyzed the traffic, noting the TV "continuously scanned our LAN."

LG's privacy policy permits collection of IP address, geographic location, nearby Wi-Fi network details, and other networked devices. However, GamersNexus has not yet demonstrated active exfiltration of this data to LG servers, only showing a blurred Wireshark capture. The investigation underscores risks inherent in ad-driven smart TV ecosystems.