A security researcher has demonstrated on camera what privacy advocates have warned about for a decade: the smart TV in your living room is a listening device first and a television second. In footage now circulating on Telegram, the researcher shows an LG G5 television with an active microphone capturing and storing everything said in the room — and here is the part that should stop you cold — it keeps recording even with the network cable unplugged. The moment the TV goes back online, the stored audio is exfiltrated through known vulnerabilities to whoever holds remote access.
“This LG TV has a microphone connected to it and right now it’s listening to me and saving the information,” the researcher states in the demonstration. “In fact, we can even unplug the network and it’s still listening to me, and what I’m saying is being stored by someone with remote access to the TV.” The team then exfiltrated the recording through vulnerabilities after the user reconnected the network. Offline is not off. The TV simply waits.
None of this is speculative. In 2024, security firm Bitdefender published an audit of LG’s webOS platform — versions 4 through 7 — documenting four vulnerabilities (CVE-2023-6317 through CVE-2023-6320) that allow attackers to bypass PIN verification, add a privileged user profile without any user interaction, escalate to root privileges, and inject commands into the TV’s operating system. Bitdefender found over 91,000 LG TVs exposing the vulnerable service directly to the internet via a simple Shodan scan. LG was notified in November 2023 and took nearly five months to ship a patch — and a patch only protects the fraction of owners who actually install updates on a television.
The video’s premise — that the TVs were cheap for a reason — comes straight from the industry’s own mouth. In a 2019 interview with The Verge, Vizio CTO Bill Baxter admitted that the company doesn’t need margin on the hardware because it makes its money after the sale: “You sell some movies, you sell some TV shows, you sell some ads.” Asked whether Vizio could hit its low price points without collecting viewer data, Baxter conceded a “dumb” TV would have to cost more at retail. Two years earlier, the FTC had already fined Vizio $2.2 million for silently tracking the second-by-second viewing habits of 11 million televisions and selling that data to third parties — matched to IP address, and from there to household identity — without consent.
The offline-recording capability demonstrated in the video has a documented pedigree in the intelligence world. The WikiLeaks Vault 7 release exposed “Weeping Angel,” a CIA and MI5 tool for Samsung smart TVs that placed the set into a “Fake-Off” mode — screen dark, LEDs off, owner convinced the TV was powered down — while the microphone kept recording for later collection. Samsung itself warned users in its own 2015 SmartTV privacy policy not to discuss “personal or other sensitive information” in front of the television, because spoken words are “captured and transmitted to a third party.” Even the FBI’s Portland field office issued a public advisory in 2019 warning that smart TV microphones and cameras are a beachhead into the home network.
Mainstream tech coverage spent years filing all of this under paranoia while reviewing the picture quality. But the record is public: the CVEs are in the National Vulnerability Database, the FTC settlement is on the government’s own website, the CIA tooling is documented, and the manufacturer admission is on tape. A device with a microphone, a network connection, root-level vulnerabilities, and a business model built on harvesting what it observes is not a television with a spying problem. It is a surveillance node with a screen attached — and it was priced to make sure one ended up in every home.
Source: STRANGER THAN FICTION NEWS
