On September 8, 2026, Matt Johansen posted that the Gamers Nexus LG investigation was insane. A two-hour video, he wrote, and here is a summary of every finding they highlight. A laundry list of privacy flaws, and some remote code execution bugs for fun.

Matt Johansen's post linking a summary of the Gamers Nexus LG investigation.
Matt Johansen, 8 Sep 2026. Screenshot of the X embed.

Gamers Nexus dropped part two on LG, he wrote, and it makes the monitor adware story he covered in July look like a warm-up. Most of this needs no exploit and no unusual setup. You buy the TV, you plug it in, this is what it does.

Cover image from Matt Johansen's X article about the Gamers Nexus LG investigation.
Cover image from his post.

It inventories the devices on your network, he wrote: staff phones with usernames attached, smartwatches, an editing box running TeamViewer, internal servers, switches, printers, 3D printers, thermostats. Names, MACs, internal IPs.

Redacted list of devices found on the Gamers Nexus network, with names and internal IPs.
Network inventory from the investigation, in his post. Some names are redacted; some first names remain.

Execs bragging they can extend ad campaigns to other devices in the household, he wrote.

Still from the Gamers Nexus video, in Johansen's post: a campaign-footprint overlay on a studio shot.
A still from the video, in his post.

Everything said near the TV ends up on it as plaintext, he wrote. Speech-to-text lands in debug logs. Researchers read a fake Social Security number mid-conversation and showed it plain on the wire.

Monitor showing webOS logs with spoken birthday and Social Security number queries.
Speech-to-text in the logs, in his post.

Using it as a dumb monitor does not stop automatic content recognition, he wrote. It fingerprints what is on the screen and what comes out of the speakers, including over HDMI. What you are watching is sent in cleartext: LG Channels sends DNS queries naming the channel, readable on the LAN.

Wireshark packet list with a DNS query to an nbcuni host highlighted.
Packet capture from the investigation, in his post.

The listening window outlives the command, he wrote. It stays open 10 to 15 seconds after speech stops. The mic off switch only kills one mic. The remote, HDMI audio, a USB webcam, Bluetooth, and a leftover speaker mic remain capturable. Pulling the network is not a clean escape. A G5 with a built-in mic kept capturing and storing with the cable out. They retrieved it after reconnect.

Then the attacker side, he wrote. Non-interactive remote code execution, still inside a disclosure window, so we do not have details. Nobody proved LG is actively listening to your living room. What is proven is that the hardware, the storage, the transcription, the logging, and the exfil path all exist, and that a hacker who gets in inherits all of it.

The advice is thin and not a 100% fix, he wrote, but they all said to keep these smart TVs off your network. Feed the panel HDMI from something you trust and treat the smart part as a defect you paid extra for.