LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
security

LG accused of 'egregious invasion of privacy' over TV data collection

Claims follow scrutiny over monitors installing adware without user consent

zeroday.news ·

LG is once again facing scrutiny over allegations that its smart TVs extensively collect user data, including audio, even when the display is in standby mode. These claims, made by researchers from the Gamers Nexus YouTube channel, follow earlier reports in July that LG monitors were installing adware without explicit user consent.

The researchers claim that their analysis of network traffic and internal data from LG smart TVs revealed plaintext transcripts generated from captured audio. This audio capture allegedly continued even when the TV was disconnected from the internet, with data stored locally and transmitted once connectivity was restored.

Beyond audio, the Gamers Nexus team reported observing the TVs collecting IP addresses, location data, and details about nearby Wi-Fi networks, including names, signal strengths, and channel numbers. The TVs also reportedly enumerated other devices on the local network that were not paired with them, such as smartphones, smartwatches, routers, thermostats, air purifiers, server baseboard management controllers, and PCs. According to the researchers, Wireshark packet capture analysis showed a significant volume of private data being collected as native behavior of LG's equipment, which they described as an "egregious invasion of privacy." The team also indicated they are working with security researchers to responsibly disclose potential vulnerabilities, including a claimed remote code execution flaw.

LG has previously stated to other publications that its TVs do not "collect, record, or store ambient conversations" and that voice recognition is an optional feature that processes voice data only when activated by the user.

LG openly acknowledges that its hardware integrates technology from its advertising division, LG Ads Solutions. In 2022, the company announced that automatic content recognition (ACR) technology, initially limited to its US smart TVs, would be rolled out to sets in 27 countries. LG stated that the insights derived from this ACR data are anonymized and handled in compliance with privacy regulations, allowing advertising customers to measure campaign effectiveness and track app registrations or service sign-ups.

However, the researchers contend that LG's product descriptions and marketing materials do not clearly disclose the extent of data collection, particularly the alleged audio capture during standby. While LG's website mentions "Intelligent Voice Recognition" and "Clear Voice Pro," detailed privacy information is reportedly difficult to find, often requiring users to navigate through multiple links on a lengthy product page. The researchers claim that all collected data is sent to LG Ads Solutions, which markets its ability to offer "precision targeting at the device level, across households" and reach 363 million "addressable secondary devices" in addition to 49 million LG TVs in the US.

These latest allegations come less than two months after Gamers Nexus reported that connecting certain LG monitors to an online Windows 11 PC could trigger the installation of the LG Monitor App through Windows' device metadata system. This behavior reportedly occurred if a user selected "Recommended Settings" during Windows setup and was signed into the Microsoft Store. The LG Monitor App Installer was found to have limited utility and displayed pop-up promotions for McAfee. LG responded at the time, stating that "McAfee is not installed automatically and is never installed without the user's explicit consent."

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.