Skip to main content
Insights · Cybersecurity

The television is listening.And so is the panel on the bedroom wall.

CyberPlus
7 min read
Private Client & Maritime Privacy
Read

On 7 September 2026, a two-hour technical investigation into LG smart televisions established that tested sets recorded clean room audio while the screen appeared to be off, stored spoken words as readable text on the device, continued saving that data while disconnected from the network, and uploaded it once connectivity returned. The webOS platform those sets run on is installed in more than 200 million televisions worldwide.

The question owners, captains and estate managers have put to us since is whether this is an LG problem or an industry problem. Our assessment is that it is both. It is also, we would argue, the wrong device to worry about most.

Four common in-room exposures with occupants present
Figure 1  Common in-room exposures, with occupants present. A study meeting overheard by a wall panel, a bedroom television facing the bed, a person bathing beside a sealed tablet, and a family profiled by automatic content recognition.

What the investigation found

The work, published by Gamers Nexus with Level1Techs and independent researchers, examined current retail OLED models using packet capture, firmware analysis and rooted-device log inspection. Five findings matter for private environments.

1. Standby audio capture.

A compromised set recorded room audio while the screen appeared powered down. The microphone hardware remains live regardless of screen state.

2. Plaintext speech logs.

Speech-to-text files recovered from the device contained spoken phrases, including conversation continuing some ten to fifteen seconds after a voice command had ended. The audio was not reduced to abstract wake-word features. It was transcribed and stored as readable text.

3. Store-and-forward while offline.

With the network cable removed, the set kept saving voice input locally and uploaded the stored files once access was restored. Unplugging a television for a sensitive conversation is not a control.

4. Network reconnaissance.

Out of the box, tested sets enumerated other devices on the local network — phones, computers, printers, switches, smart-home hardware — and collected nearby Wi-Fi network names and signal data, feeding an advertising business that markets reach into the secondary devices it discovers.

5. Undisclosed remote-code-execution flaws.

Vulnerabilities in network-facing webOS services were reported to the manufacturer and remain under responsible disclosure. There is no public evidence of exploitation in the wild, but always-on network listeners, live microphones, offline storage and remote code execution together describe the architecture of a surveillance implant.

No firmware fix had been published at the time of writing. Whatever remediation follows, the structural lesson stands: the only behaviour that required an exploit was the audio leaving the building. The tracking, the transcription and the network scanning were product features.

Is it just LG?

Two problems need separating. The first is intentional collection: the advertising business every platform runs. Automatic content recognition ships enabled by default under a deliberately bland name on effectively every consumer platform — Viewing Information Services on Samsung, Live Plus on LG, Viewing Data on Vizio, Smart TV Experience on Roku, Samba Interactive TV on Sony. It samples what is on screen across all inputs, including HDMI from an external box, and matches it against content databases to build a viewing profile that is sold onward. A 2024 study by UC Davis, UCL and Universidad Carlos III measured Samsung sets fingerprinting roughly every minute and LG sets roughly every fifteen seconds, and confirmed that the tracking continues when the television is used purely as a dumb display.

Opt-outs exist on every platform, but they are fragmented across several menus and have been observed reverting after firmware updates — a pattern that prompted the FTC to revisit Vizio’s 2017 consent decree this year. On intentional collection, in other words, the market is near-uniform.

The second problem is exploitable weakness, and there the record moves between brands rather than belonging to one. Vault 7 documented an intelligence-agency tool that placed Samsung sets into a fake-off mode in which they recorded room audio. Bitdefender rooted LG sets over the network in 2024, when more than ninety thousand were found directly exposed to the internet. Consumer television firmware across all brands shares the same characteristics: long update tails, abandoned models, bundled third-party software, and network services listening by default.

The correct planning assumption is that any consumer smart television, of any brand, may be remotely compromisable at some point in its service life — and that the owner will have no way of knowing when.

The device nobody audits

Televisions are not the most privileged devices in a significant property. Nearly every residence, superyacht and VIP aircraft cabin in this segment runs an automation platform — Crestron, Control4, Savant, Lutron, KNX — and that platform deserves more attention than any screen.

The in-wall touch panels are the visible half. One sits in every controlled room, including the master suite, the bathrooms and the owner’s study. Each is permanently mains-powered, permanently networked, and fitted with a microphone for intercom and voice control and, on many models, a camera. Unlike a television, a panel is never off, is rarely if ever factory-reset, and its firmware is updated only when an integrator chooses to visit.

Master suite showing a television and in-wall control panel aimed at the bed
Figure 2  The master suite. The same television that plays a film is aimed at the bed, microphone live even in standby, while the in-wall control panel adds a second microphone and camera.

The invisible half is the central processor. It holds credentials and control paths into the AV matrix, lighting, blinds, door locks, CCTV, HVAC and often the network switching itself, and it typically has visibility of every VLAN so that it can drive devices on all of them. Compromise of the processor, or lateral movement from a single panel, yields simultaneous eyes and ears in every room plus manipulation of the physical security systems. That is a materially worse outcome than any single television.

This is not theoretical. At DEF CON in 2018 a researcher disclosed more than two dozen vulnerabilities in Crestron devices, demonstrating remote recording of room audio from panel microphones and live streaming from panel webcams. Presentation gateways from the same vendor carried remote command-execution flaws in 2016 and again in 2019. In 2026 a remote-code-execution vulnerability was published in current touch panels, exploitable through a hidden console command to take control of the underlying embedded Linux system. The pattern across a decade is consistent: these are embedded computers with microphones, shipped in volume, patched slowly, and installed by third parties.

The operational picture compounds the technical one. Automation systems are almost always maintained by an external integrator who retains standing remote access for support, frequently through always-on tunnels or cloud management portals, sometimes with credentials shared across their whole client base. The client rarely knows what access exists. The integrator’s own security becomes the property’s security, and a compromise at a single audiovisual firm can quietly expose every residence and vessel on its books.

Diagram of the automation layer as an attack surface
Figure 3  The automation layer as an attack surface. Internet-facing services and standing integrator access in front, microphone- and camera-equipped panels in every room behind, and privileged control of the physical subsystems beneath.

Capture, storage, exfiltration

Hostile collection requires three things, and a monitoring programme that watches only one of them will miss real attacks. Capture is the transducer or radio doing the collecting: a microphone or camera in the room, or a covert implant transmitting on its own channel that never touches your network at all. Storage is the captured material held on the device, which the LG findings showed persisting through screen-off and network disconnection until an opportunity to transmit arose. Exfiltration is the data leaving — over the property’s own links, over a radio side-channel, or physically, by someone reading the device out over USB during a service visit.

Each stage has its own detector, and only the combination is credible. RF spectrum monitoring and TSCM sweeps address capture and radio side-channels. Configuration audits and periodic device forensics address on-device storage. Continuous DNS and egress monitoring, applied to every WAN path rather than only the primary one, addresses network transmission — and given the store-and-forward behaviour demonstrated, a burst of uploads from a device that has just regained connectivity is precisely the signal to catch. Escorted access, port control and an accurate asset register close the physical route.

Diagram of capture, on-device storage and exfiltration with the detection layer
Figure 4  How data leaves a high-privacy area. Capture, on-device storage and exfiltration, with the detection layer that must cover each stage. Note the two paths network monitoring alone can never see: radio side-channels and physical recovery.

The placement decision

Segmentation only protects you if each device is assigned to the right segment, and that assignment is a judgement rather than an afterthought. The default reasoning is dangerously simple: an in-room television or tablet is just a screen for viewing content, so it goes on the entertainment network alongside the media server and the streaming boxes. For a saloon or cinema screen, that is reasonable.

But the classification is being made on what the device plays, when the risk comes from what the device can capture and where it is pointed. A television on the AV network in the master bedroom, with a live microphone and a camera aimed at the bed, is not an entertainment device in any sense that matters to security. It is a capture device in the most sensitive room in the property, and the AV segment — comparatively open, internet-connected for streaming, shared with dozens of other devices — is exactly the wrong place for it.

Diagram of network segments and the device placement decision
Figure 5  The standard segments of a securely designed private network, and the placement decision that undoes them if it is made carelessly.

A device is not classified by what it plays. It is classified by what it can capture, and where it is pointed.

A screen in a bedroom, bathroom, dressing room or private office is a sensitive-room capture device regardless of what it is used for, and belongs on an isolated segment with no internet path — or, for the panel driving a bedroom television, on no network at all, fed content only over HDMI from a vetted external box. Where a device combines functions, it inherits the stricter of the two placements. Every placement decision should be recorded in the asset register against the device, so that it can be reviewed rather than silently inherited from whoever installed it.

A tablet sealed in a waterproof enclosure beside a shower
Figure 6  The sealed bathroom tablet. A device chosen for music and video brings two cameras and several microphones into the room with the highest privacy expectation in the property, in an enclosure that is rarely opened and never inspected.

Questions worth asking this week

  1. Which screens and panels in the principal’s private rooms have a microphone or camera, and which of those are still connected to a network?
  2. Does your integrator hold standing remote access to the automation platform, and can you produce an inventory of who holds which credentials?
  3. Were microphone- and camera-free panel variants specified for bedrooms, bathrooms and the study — and if not, can the transducers be disabled at the next refit?
  4. Is egress policy enforced identically across every WAN path, including VSAT, Starlink and cellular, or only on the primary link?
  5. When was the last technical sweep of the primary bedrooms and offices, and what has changed in the property since — a refit, a charter, a contractor visit?
CyberPlus Insights · Conclusion

None of this argues against screens or automation in beautiful spaces. It argues for treating them as what they now are: computers with senses, and with control of the building.

Placement is the control that cannot be undone by a firmware update, which is why it comes first. Keep microphones and cameras physically out of intimate and commercially sensitive rooms. Never give a television internet access. Strip the automation layer of standing external access and of transducers it does not need. Deliver content through a small number of vetted external devices.

Then verify continuously, with radio, device and network monitoring, rather than trusting settings menus that have repeatedly been observed to revert.

The person in the shower cannot see an indicator dot, and a standby screen reveals nothing. Assurance has to come from outside the device.

The full white paper

This article is drawn from The Television Is Listening, third edition, September 2026 — the vendor-by-vendor assessment, the risk matrix by zone, the full hardening guide and the continual assurance programme.

Download the white paper →PDF · 2.2 MB

The threat is real. The solution is proven.

Let's Talk