What we found
Hisense Smart TV: DVIDAA OS captures 7,200 screenshots/hour of what you watch via ACR.
The app requests RECORD_AUDIO (microphone access), ACCESS_FINE_LOCATION (precise GPS), ACCESS_COARSE_LOCATION, READ_PHONE_STATE (device identifiers), GET_ACCOUNTS (user accounts on device), WRITE_SETTINGS (modify system settings), and MOUNT_UNMOUNT_FILESYSTEMS. A TV remote control app has no legitimate need for continuous microphone access, precise GPS location, access to all accounts on the phone, or the ability to mount/unmount filesystems. The app also uses MIPUSH_RECEIVE (Xiaomi push service), indicating Chinese push notification infrastructure.
TCL Smart TV: DRoku TV OS inside. ACR captures what you watch and sells it to advertisers.
CVE-2020-27403: TCL shipped TVs with an undisclosed web server running on non-standard port 7989 that exposed the entire filesystem — including personal data, images, and security tokens — to any unauthenticated attacker on the local network. TCL silently patched it without any public disclosure.
Crystal UHD DU7200 (2024): CSamsung told customers their voice data was encrypted when sent from the TV.
EPIC's 2015 FTC complaint documented that Samsung transmitted voice recordings from SmartTV voice recognition to Nuance Communications without encryption. Security researchers independently confirmed they could decode the voice audio in transit, enabling eavesdropping on conversations in users' homes. Samsung's privacy policy explicitly claimed encryption was used, which was demonstrably false.
Roku Smart TV: CYour TV is an ad platform that happens to show content. ACR watches everything you watch.
Michigan AG (April 2025) and Florida AG (October 2025) both sued Roku alleging the company secretly collected children's personal information — including precise location data, IP addresses, viewing histories, voice recordings — and shared it with advertisers and data brokers without COPPA-required parental consent. Florida's suit is the first under the Florida Digital Bill of Rights. Roku failed to implement age verification or obtain any parental consent.
M-Series Quantum SmartCast: CVizio now claims you have to choose to turn on viewing data collection.
FTC settlement (2017) proved Vizio installed ACR software on 11 million smart TVs that collected viewing data on a second-by-second basis without consumer knowledge or consent starting February 2014. The "Smart Interactivity" feature was turned on by default. Vizio collected over 100 billion data points per day from unknowing users. Settlement required $2.2 million payment.
OLED65C3PUA (C3 OLED evo): CLG says you can choose whether your TV watches what you watch.
LG ThinQ companion app (com.lgeha.nuts) requests 39 permissions including ACCESS_BACKGROUND_LOCATION, ACCESS_FINE_LOCATION, CAMERA, RECORD_AUDIO, READ_CONTACTS, WRITE_CONTACTS, READ_PHONE_STATE, and GET_ACCOUNTS. The app embeds 14 third-party trackers including Google AdMob, Facebook Analytics, Salesforce Marketing Cloud, and Treasure Data — all advertising and data monetization platforms. LG requires acceptance of ALL user agreements (viewing information, voice assistant, cross-device advertising) to use any smart TV features, making opt-in effectively mandatory.
Bravia 7 (XR70): CYou paid $2,000 for a Sony Bravia TV.
Sony Bravia ships with Samba TV ACR embedded in firmware — capturing a screenshot every 500ms (2 per second). Data includes show, season, episode, household ID, location, and timestamp. Texas AG Ken Paxton sued Sony in December 2025.