The cited sources give this account: Smart TVs, including LG models, collect and sell user data through built-in technologies like ACR, often without explicit consent. These devices can track viewing habits, conversations, and other personal information, posing significant privacy and security (ad) risks. LG's G5 smart TVs, for instance, crawl local networks to track and report back on all connected devices, and are equipped with microphones that can record conversations even when voice command is not activated or requested. The onboard computer of these TVs is riddled with security vulnerabilities, making them a potential point of entry for attackers, especially in business meeting rooms and medical environments where sensitive personal information is displayed.
LG executives (ad) have bragged about their ability to track users' viewing data, presuming that purchasing their TV should give them a permanent foothold within your home to harvest your viewing data and maybe also spy on you and your family. While some users may disconnect their TVs from the internet, the onboard computer can store data offline until an internet connection becomes available, making it a persistent threat.
The practice of selling user data to advertisers is not unique to LG, as every smart TV brand on the market (ad) now subsidizes their costs by selling user data to advertisers, often making more from this than their actual TV sales.
Informed (ad) consent is also a big problem, as most TVs obfuscate what users are consenting to through deceptive language or dark pattern UI designs or by simply forcing you to hit okay and agree to tracking in order to process through basic setup.
Experts recommend disabling or opting out of any tracking, and using tools like Pi-hole to block this type of data from being exfiltrated from your network completely. This is especially important for LG and other smart TVs, which can track and report (ad) back on all connected devices, even when the screen is off. These TVs often have security vulnerabilities and can be a potential point of entry for attackers, particularly in business and medical environments.