SECURITY · NEWS ANALYSIS

The Smart TV Listening Claims: What Connected Devices Collect, What You Agreed To, and What Is Left on Them

In September 2026 a group of technology researchers published a long investigation alleging that a major manufacturer’s smart televisions capture audio while idle and survey the networks around them. The manufacturer denied the central allegation in specific terms, the researchers stood by their findings, and as of this writing the technical dispute is unresolved and has not been independently verified — not by us, and not by the outlets covering it. That argument will be settled by people with packet captures and firmware, and this brief takes no side in it. What is worth attention while the experts argue is quieter and not in dispute: the devices in an ordinary living room have microphones, network visibility, and their own storage; the permissions governing all of it were granted on a setup screen that most people tapped through; and when those devices are eventually replaced, almost nobody treats them as data-bearing equipment. That last part is our business, and it is the part nobody is covering.

By Brian Boynton Published 9 min read

STRAIGHT ANSWER

Researchers alleged a major manufacturer’s smart TVs capture audio while idle; the manufacturer denies it, and the dispute is unresolved. The durable lesson does not depend on who is right. Connected devices have microphones, network visibility, and local flash storage holding Wi-Fi credentials, account tokens, and logs; consent lives in terms of service nobody reads; and at disposal a factory reset is a convenience feature, not verified sanitization under NIST SP 800-88.

01 / THE DISPUTEAn allegation, a denial, and an unresolved question

In the first week of September 2026, the technology outlet Gamers Nexus published a lengthy investigation conducted with Level1Techs and independent security researchers, alleging that LG smart televisions collect more than their owners understand. The allegations, as reported, include that the sets process and queue audio while idle or disconnected and transmit it when connectivity returns, that they survey the wireless networks around them and catalog nearby devices, that unmatched voice interactions are retained as plain text, and that the investigators found security vulnerabilities in the platform. The researchers framed the scale of the issue around a figure of 216 million televisions. It is worth noting that the reporting also records LG’s own installed-base numbers as roughly 49 million sets in the United States and 216 million worldwide, so the headline figure appears to describe the global fleet rather than the American one — a detail that illustrates how much care these numbers need before anyone repeats them.

LG denied the central allegation, in specific rather than general terms. The company said its televisions “do not continuously record or transmit” conversations; that voice data is processed only when a user presses and holds the voice button on the remote, or when a recognized wake word is detected after the owner has turned on the Far-Field voice recognition feature; that audio is deleted when no wake word is recognized; and that Automatic Content Recognition, voice recognition, and interest-based advertising are opt-in features that can be turned off. LG characterized the investigation as resting on misconceptions and said it remains committed to transparency about how its connected products work. The company also acknowledged, reasonably, that no connected product is ever completely immune from security vulnerabilities.

The researchers rejected the denial and stood by their findings, saying their investigation included demonstrations and proofs of concept, noting that LG’s statement did not address the security vulnerabilities they reported, and inviting the company to publish evidence contradicting them. Reporters covering the story have been careful to say they have not independently verified either the investigators’ claims or the company’s counterclaims. Several accounts note that LG’s statement responded to continuous real-time recording, while the investigators described intermittent buffered logging, which means the two sides may not be answering the same question.

That is where the matter stands. CyberCrunch has no relationship with LG, with the investigators, or with any party to this dispute, we have not tested any of the hardware, and we take no position on who is right. The technical argument will be settled by people with packet captures, firmware, and, if it goes that far, regulators or a court. Everything below is about the questions that remain worth asking whichever way it resolves.

02 / CAPABILITY VS. CONDUCTWhat these devices can do is not in dispute

Strip out the contested findings and a plain description of the hardware remains, and nobody disagrees about it. A modern smart television has one or more microphones, because voice control is a selling feature. It sits on your network with visibility into what else is there, because device discovery is how streaming and casting work. It has a processor, an operating system, an application store, and its own storage, because it is a computer. The same is true of the speaker on the kitchen counter, the video doorbell, the thermostat, the camera in the nursery, the printer, the car in the driveway, and a growing share of ordinary appliances.

Capability is not conduct, and it would be unfair to treat a microphone as proof of eavesdropping. But capability is what makes conduct a question worth asking, and it is why these disputes keep arriving. The honest position for a consumer or an IT manager is not paranoia and not dismissal. It is that these devices can collect a great deal, that what they actually collect is governed by settings and policies you rarely see in operation, and that the difference between the two is visible only to someone doing the kind of work the investigators in this story were doing.

A microphone in a device is not evidence of misconduct. It is evidence that the question is worth asking — and that the answer lives somewhere you have not read.

There is also precedent that this category of concern is not hypothetical. In February 2017 the Federal Trade Commission and the New Jersey Attorney General settled charges against Vizio over collecting viewing histories from 11 million smart televisions without consumers’ consent; Vizio paid 2.2 million dollars and agreed to obtain express consent going forward. Different company, different data, different facts from the current allegations, and cited here only for the narrow point it establishes: undisclosed collection by a connected television has happened before and regulators have treated it as actionable.

Here is the part of this story that should be uncomfortable regardless of how the LG dispute resolves. Almost every disputed data practice in consumer technology ends up in the same place: a terms-of-service agreement, a privacy policy, and a sequence of setup screens that the owner accepted in order to finish plugging in the television. Whether that constitutes meaningful authorization is the whole argument, and it is one companies generally win, because the agreement was presented and accepted.

The manufacturer’s position in these disputes is usually that the features are disclosed, optional, and consented to. That position is often accurate as a matter of documentation. The owner’s experience is that setup involved several screens with a large highlighted button that advanced to the next step, that reading the policy would have taken longer than mounting the television, and that nobody in the household who later spoke in that room agreed to anything at all. Both things are true at once, and the gap between them is where the surprise lives.

Some practical discipline, for a household and even more for an organization:

  • Read the setup screens once, at setup. That is the only moment when the choices are in front of you and reversing them is free. Decline what you do not want; you can turn features on later if you miss them.
  • Find the privacy menu after setup and go through it. Content recognition, personalized advertising, voice services, and diagnostics are usually separate toggles in separate submenus. Manufacturers state these are optional; the only way to know your own device’s state is to look.
  • Read what the terms say about collection, sharing, and retention specifically. Not the whole document: search it for those three ideas. What is collected, who it goes to, and how long it is kept are the three answers that determine your exposure, and the third one is the one most often left vague.
  • For business deployments, that reading is a procurement step, not a personal chore. A display in a conference room or a voice device in a lobby is a vendor relationship subject to your third-party risk process, and the terms of service are the contract. If the terms permit collection your policies prohibit, the time to discover that is before purchase.
  • Segment what you cannot govern. Consumer devices that must be on a network but do not need to see anything else belong on a guest or isolated network. This is standard practice in enterprises and worth an evening at home.

04 / THE PART NOBODY COVERSWhat is still on the device when you get rid of it

Coverage of stories like this one ends when the argument ends. The device, meanwhile, continues to exist. A television bought today will likely be in service for a decade, and then it will be sold, given away, put at the curb, or handed to whoever hauls away the old one when the new one is delivered. At that moment it stops being a privacy question and becomes a disposal question, and this is the part that receives almost no attention.

What is on it depends on the product, and manufacturers seldom publish a storage map. The common pattern is that a connected device holds the name and password of every wireless network it has joined, authentication tokens for the accounts signed into it, a record of devices it has paired with or discovered, application data and caches, and diagnostic and event logs. Whether audio or video is retained locally is product-specific, and in the present dispute it is exactly what is contested. But the credentials and tokens are not contested by anyone. A television that has been on your network knows how to get back onto it.

The storage is almost always embedded flash soldered to the board, which matters for a reason people underestimate. A factory reset is a convenience feature written by the manufacturer, not a sanitization method. On flash media it generally clears settings and pointers while the underlying cells retain data until overwritten, and wear leveling means even an overwrite does not reach every block. This is the same physics that makes SSD sanitization its own discipline: NIST SP 800-88 Rev. 2 and IEEE 2883-2022 both treat flash separately from magnetic media and both make verification the point (the SSD, SED and NVMe field guide covers the methods, and the Data Destruction Field Manual covers the decision by media type). Cryptographic erase works where the device implements it; most consumer appliances do not expose that capability to their owners. Where a device cannot be verifiably purged, physical destruction of the storage is the method that can be evidenced.

A factory reset is a setting, not a standard. On embedded flash it clears what you can see, not what is there — which is why disposal of a connected device is a media question, not a recycling question.

Practically, at end of life:

  • De-provision before you dispose. Sign the device out of every account, remove it from the manufacturer’s app and from any management platform, revoke tokens, unpair it, and then factory reset. This removes the device’s live access even where it does not remove the stored bytes.
  • Change what the device knew. If it stored a wireless key that other devices still use, rotate it. This one step neutralizes the most likely real-world harm.
  • Decide by sensitivity, not by device category. A television that only ever streamed video is a different risk from a conference-room display that joined a corporate network, a camera with recorded footage, or a printer that spooled documents. The second group belongs in certified destruction with a record.
  • For organizations, put them on the inventory. Room displays, voice devices, cameras, access panels, and printers are data-bearing assets with serial numbers, not facilities surplus. They should leave under the same chain of custody as laptops, with a certificate of destruction naming the method — the argument the office move playbook makes for every device in a building and The Copier Went Home makes for the one everybody forgets.
  • Do not hand a connected device to an uncertified hauler. A device with storage on it should go to a provider that will tell you what happened to that storage. The certified versus free pickup brief covers what the free option leaves out.

None of this requires resolving the argument that started it. Whether the allegations in this case are correct, overstated, or mistaken, the television in the conference room still knows the wireless key, and it will still be sitting on a loading dock one day.

05 / FAQConnected devices and disposal FAQ

Is it proven that smart TVs record conversations?

No. What exists at this point is an allegation and a denial. In September 2026 the technology outlet Gamers Nexus, working with Level1Techs and independent security researchers, published an investigation alleging that LG smart televisions process and queue audio while idle, among other findings. LG denied the central claim, stating that its televisions process voice data only when the remote's voice button is pressed or a recognized wake word is detected after the Far-Field feature is turned on, that audio is deleted when no wake word is recognized, and that content recognition and interest-based advertising are opt-in. The researchers stood by their work and asked LG to publish contrary evidence. Neither CyberCrunch nor, at this writing, the outlets covering the story have independently verified either side. Separately from this dispute, it is established that smart televisions are capable of collecting viewing and audio data, and that regulators have acted on such collection before.

Has a smart TV maker ever actually been penalized for collecting data without consent?

Yes, and it is the cleanest precedent for why the consent question matters regardless of how the current dispute resolves. In February 2017 the Federal Trade Commission and the New Jersey Attorney General settled charges against Vizio over the collection of viewing histories from 11 million smart televisions without consumers' consent, with Vizio agreeing to pay 2.2 million dollars and to obtain express consent going forward. That case concerned viewing data rather than audio, and it involved a different manufacturer and a different set of facts than the present allegations. It is cited here only to establish that undisclosed collection by a connected television is a thing that has happened and that regulators treat as actionable.

Does a factory reset remove my data from a smart TV or speaker?

Not reliably, and not verifiably. A factory reset is a convenience feature written by the manufacturer, not a sanitization method, and on devices built around embedded flash it typically clears pointers and settings rather than purging the underlying media. NIST SP 800-88 Rev. 2 and IEEE 2883-2022 describe verified approaches for flash, including cryptographic erase where the device supports it and physical destruction where it does not, and the distinguishing feature of both is verification you can evidence. For a household device with nothing sensitive on it, a reset plus removing the device from your accounts is a reasonable step. For a device that held credentials, camera or audio history, or business network access, treat it as a data-bearing asset.

What is actually stored on a smart TV, speaker, or camera?

It varies by product, and manufacturers rarely publish a storage map. The common pattern is that the device holds Wi-Fi network names and credentials, tokens for the accounts you signed into (streaming services, cloud accounts, sometimes email), records of paired and discovered devices, application data and caches, diagnostic and event logs, and any media the device stores locally, all on embedded flash soldered to the board. Whether audio or video is retained on the device is product-specific and, in the current dispute, precisely what is contested. The practical assumption for disposal is that the device knows your network and your accounts even if it knows nothing else.

Our business has smart TVs and voice devices in conference rooms. What should we do with them at refresh?

Put them on the asset inventory as data-bearing and treat them the way you treat a laptop. Before disposal, sign the device out of every account, remove it from your mobile device or network management system, revoke any tokens or API access it held, and change any credentials it stored, particularly a shared wireless key. Then route it through your ITAD provider with a serial number rather than to a facilities recycling pallet, and take the certificate. Conference-room displays, room systems, and voice devices sit on a corporate network and hold credentials for it, which is the same reason badge systems and copiers belong on that inventory.

IF IT HAS STORAGE, IT HAS A DISPOSITION

Displays, room systems, cameras, and printers are data-bearing too

CyberCrunch inventories connected devices by serial, sanitizes or destroys the media under NIST SP 800-88 and IEEE 2883-2022, and returns a certificate for each — including the embedded flash that a factory reset does not reach. NAID AAA, R2v3, RIOS, and PA DEP certified, on-site or at our facility, in all 50 states.

This brief is a news analysis reflecting public reporting as of September 18, 2026 — the Gamers Nexus investigation published with Level1Techs and independent researchers, LG’s public response as reported by Tom’s Hardware (September 9), Al Jazeera (September 10), Engadget (September 12), and Information Age (September 14), and the Federal Trade Commission’s February 2017 announcement of the Vizio settlement. The allegations described here are allegations: they are disputed by LG, they have not been independently verified by CyberCrunch or, at this writing, by the outlets reporting them, and nothing in this brief should be read as a finding that any company engaged in the conduct alleged or violated any law. CyberCrunch has no relationship with LG, Gamers Nexus, Level1Techs, or any other party to the dispute, has not tested any of the devices discussed, and takes no position on the technical questions at issue. Descriptions of device storage and sanitization are general and product-specific behavior varies. This is not legal advice; the Vizio matter is described from the FTC’s public announcement and is cited only as precedent that regulators have acted on undisclosed collection, not as a comparison to the present allegations.