If you can firewall your LAN - you can also firewall your WiFi.
IMO, the moment a device starts doing that, I’m setting it on fire.
Huh? Your WiFi is (part of) your LAN.
I’m pointing out safe or not has nothing to do with it being on a LAN or not.
Notably, a device can even route all command and control through a cloud service, including sending copies/hashes of all accessed content AND also serve just local (as in physically connected) media/content, if it has a network connection.
This has been an issue since BluRAY at least, where players have the capability to check physical media licensing and deny/brick BluRAY media based on network updates of the keys, and could run Java apps which had network access. So at least 20 years? It is a big reason why there was resistance to BluRAY vs DVD, as DVD was a relatively dumb player.
The only way to prevent that is to firewall off or physically disconnect any network access. Which is getting harder to do with cheap LTE modems.
In this example, for instance, I bet these LG TV’s will happily send all this info even if no one is using any network or app based media streaming at all.
I'm not really sure what the disconnect is here. This seems like the obvious meaning of "works over the LAN" and it means, by definition, that you can control the device without letting it access the manufacturer's servers.
A LAN (or WiFi) typically has routability to the Internet (though doesn’t have to, of course!) which is why what you are saying is confusing. It has for at least 20 years, and is especially true in residential, but also true even in commercial.
Those some IP addresses could also be NAT’d, and often are.
Most modern products have also spent significant R&D figuring out how to bypass NAT and firewalls and even hide from packet inspection (tunneling DNS and command and control over HTTPS, for one example).
Very few people are able to handle or setup actual air gapped LANs now (or isolated VLANs), but anything besides that is risky in these scenarios.
Are you real?