← Smart TVs
D

Crystal UHD DU7200 (2024)

Serious concerns
Samsung · 🇰🇷 South Korea · WiFi + Bluetooth
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
FCC ID: A3LWID210S
Chipset: Samsung Crystal Processor 4K (MediaTek-based)
App: com.samsung.android.oneconnect
Manufacturer: Samsung

⚠️ The bottom line

Samsung says it watches what you view on your TV to give you better recommendations. In reality, the TV takes a screenshot every half second of everything on screen — including content from your gaming console, laptop, or DVD player connected via HDMI — and sends this data to Samsung's advertising servers. Samsung was sued by Texas and paid $46 million in a class action because this data was being sold for advertising, not just used for recommendations. Samsung told customers their voice data was encrypted when sent from the TV. Security researchers proved this was a lie — voice recordings were sent without encryption, meaning anyone on the same network could listen to what you said near your TV. A privacy watchdog filed a formal complaint with the FTC over this.

Legal jurisdiction
🇰🇷 South Korea (headquarters)
PIPA read more →
Strict data protection — fined Google, Meta. But National Intelligence Service has broad surveillance powers
Spying
4/4 EXTREME
Is someone spying on me?
Data Sharing
2/4 MODERATE
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Honesty
4/4 EXTREME
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
11Contradictions
3Critical
4High
4Medium
9Sources
Findings by concern
Spying 4/4 EXTREME 7 findings
⚠️ criticalmarketing vs regulatory
Your Samsung TV took a screenshot of what you were watching twice every second. Everything on screen — news, banking apps, video calls, private photos — captured and sent to Samsung. Texas sued. Samsung settled. Then Texas sued Sony, LG, Hisense, and TCL for doing the same thing. Your television watches you more closely than you watch it.

What they claim: Samsung describes Smart TV viewing data collection for personalisation

What we found: The Texas Attorney General settled with Samsung over its Automated Content Recognition (ACR) system, which captured screenshots of whatever was on screen every 500 milliseconds — twice per second. Samsung must now obtain express consent before collecting viewing data. Texas also sued Sony, LG, Hisense, and TCL for identical ACR surveillance, with Hisense receiving the first-ever temporary restraining order against a TV maker.

⚡ highpolicy claims vs firmware analysis
Samsung's privacy policy makes it sound like the TV only tracks which TV shows and channels you watch. But the tracking also captures whatever is on screen when you connect a laptop, game console, or any other device via HDMI. If you use your Samsung TV as a computer monitor, it's taking screenshots of your work too.

What they claim: Samsung's SmartTV privacy supplement describes ACR as collecting information about "channels and networks you watch" and "programs you view" — implying it only tracks broadcast/streaming content on the TV's native apps.

What we found: UCL/UC Davis research (2024) confirmed that Samsung's ACR fingerprints content displayed on ALL inputs, including HDMI. This means content from external devices (gaming consoles, laptops, Blu-ray players) connected via HDMI is also captured and fingerprinted. The $46M class action specifically noted ACR records "content displayed when the TV is used as a computer monitor." The policy language about "channels" and "programs" obscures the true scope of surveillance.

⚡ highapp permissions vs firmware analysis
To control your Samsung TV, you need the SmartThings app, which demands access to your phone calls, camera, microphone, contacts, precise location (even in the background), physical activity tracking, and the ability to see every app on your phone. Most of these have nothing to do with controlling a TV.

What they claim: The Samsung Smart TV is a television — a display device for watching content. It does not make phone calls, track physical activity, or function as a surveillance camera.

What we found: The SmartThings companion app requests 46 permissions including: CALL_PHONE, RECORD_AUDIO, CAMERA, ACCESS_FINE_LOCATION, ACCESS_BACKGROUND_LOCATION, ACTIVITY_RECOGNITION, HIGH_SAMPLING_RATE_SENSORS, READ_CONTACTS, READ_PHONE_NUMBERS, READ_PHONE_STATE, MODIFY_PHONE_STATE, QUERY_ALL_PACKAGES, WRITE_SECURE_SETTINGS, and WRITE_SETTINGS. Many of these permissions have no reasonable connection to controlling a television.

⚡ highregulatory findings vs firmware analysis
Samsung points out their TVs don't have a built-in microphone as a privacy feature. But security researchers found that someone nearby can hack the TV remote's microphone via Bluetooth, turning it into a listening device. The "no mic in the TV" claim gives a false sense of security when the remote's mic can be hijacked just as easily.

What they claim: CVE-2022-44636 (Samsung-classified as critical, SVE-2022-50125): Samsung TV smart remote control allows Bluetooth spoofing to enable microphone access. Samsung markets its TVs as not having built-in microphones — the mic is on the remote — framing this as a privacy advantage.

What we found: The remote control's microphone can be hijacked via Bluetooth spoofing (CVE-2022-44636). An attacker within Bluetooth range can spoof the remote pairing process when a user presses a button, gaining unauthorized microphone access. This means the "privacy advantage" of not having a built-in TV mic is undermined — the remote's mic is equally exploitable. Samsung's own security bulletin classified this as critical severity, yet the marketing materials continue to emphasize the absence of a built-in TV microphone.

⚫ mediumfirmware analysis vs regulatory findings
Samsung TVs have a built-in web browser, but that browser has serious security holes. If you visit a malicious website on your TV, hackers could take control of the TV itself. Since the TV already has access to everything you watch and your home network, a compromised TV is a much bigger problem than a compromised website on your phone.

What they claim: Samsung Tizen TVs include a built-in web browser based on Chromium/V8, marketed as a feature for internet browsing on the big screen.

What we found: Multiple high-severity vulnerabilities in the TV's browser engine: SVE-2022-50146 through SVE-2022-50152 (V8 JIT compiler bugs enabling remote code execution on 2020-2022 models) and SVE-2023-50069 (XML validation bypass in Chromium). Visiting a malicious website on the TV's browser could allow an attacker to execute arbitrary code on the TV — a device that has ACR access to everything displayed on screen, network access, and (via CVE-2022-44636) potential microphone access through the remote.

⚫ mediumpolicy claims vs regulatory findings
Samsung claims to take security seriously and uses its Knox brand to suggest strong protection. But over the past decade, they've been caught sending voice data unencrypted, tracking viewing habits without consent, having hackable remote microphones, and browser security holes that let hackers in. The "secure" branding doesn't match the track record.

What they claim: Samsung's privacy policy claims data is processed securely and mentions Samsung Knox security for device protection.

What we found: EPIC's 2015 FTC complaint established that Samsung transmitted voice recordings unencrypted to Nuance Communications. The $46M class action found ACR data collected without proper consent. The Texas AG found privacy prompts were misleading. CVE-2022-44636 shows the remote's mic can be hijacked via Bluetooth. V8 JIT bugs (SVE-2022-50146) enable remote code execution via the browser. The pattern across a decade (2015-2026) shows Samsung repeatedly failing to meet its own stated security commitments.

⚫ mediumfirmware analysis vs policy claims
Samsung sells these TVs as entertainment devices with fancy picture technology. But under the hood, the TV is constantly talking to advertising and tracking servers — taking a screenshot of your screen twice every second. It's really an advertising platform that happens to show you TV, not a TV that happens to show you ads.

What they claim: Samsung markets its Crystal UHD TVs as entertainment devices with "PurColor" and "Crystal Processor 4K" for an enhanced viewing experience.

What we found: The TV's firmware contacts 9+ dedicated endpoints including ACR tracking servers (acr-us-prd.samsungcloud.tv, log-config.samsungacr.com), advertising infrastructure (osb-apps.samsungqbe.com), and Samsung cloud services. The device functions as an advertising platform that also displays content — not the other way around. The ACR system captures screen fingerprints every 500ms across ALL inputs, making the TV fundamentally a surveillance device wrapped in entertainment marketing.

Data Sharing 2/4 MODERATE 2 findings
⚠️ criticalpolicy claims vs firmware analysis
Samsung says it watches what you view on your TV to give you better recommendations. In reality, the TV takes a screenshot every half second of everything on screen — including content from your gaming console, laptop, or DVD player connected via HDMI — and sends this data to Samsung's advertising servers. Samsung was sued by Texas and paid $46 million in a class action because this data was being sold for advertising, not just used for recommendations.

What they claim: Samsung's SmartTV Supplement states that viewing information is collected "to enhance video content" and provide "customised TV, movie, and other content recommendations." This frames ACR as a helpful recommendation feature.

What we found: Firmware-level ACR system captures screen fingerprints every 500ms and transmits to dedicated ACR servers (acr-us-prd.samsungcloud.tv, acr0.samsungcloudsolution.com, log-config.samsungacr.com). UC Davis/UCL research (IMC 2024) confirmed Samsung transmits up to 2x more ACR data than LG. The $46M class action settlement and Texas AG lawsuit (December 2025) established that this data is monetized for advertising — not merely used for recommendations. Samsung settled with Texas on February 26, 2026, agreeing to halt ACR collection without express consent.

⚫ mediumapp permissions vs policy claims
The SmartThings app — which you need to control your Samsung TV — secretly sends your usage data and device information to Microsoft through embedded tracking software. Samsung's privacy policy doesn't mention Microsoft by name, so you'd never know your TV remote app is reporting to Microsoft.

What they claim: Samsung's privacy policy mentions sharing data with "service providers" and "analytics companies" but does not name specific third parties receiving SmartThings app data.

What we found: The SmartThings app (v1.8.21.28) embeds two Microsoft trackers: Microsoft Visual Studio App Center Analytics and Microsoft Visual Studio App Center Crashes (identified via Exodus Privacy report). These trackers send app usage data, crash reports, and device information to Microsoft's servers. Samsung's privacy policy does not specifically name Microsoft as a data recipient, despite the SmartThings app being the primary way users interact with Samsung smart home devices including TVs.

Security 3/4 HIGH 1 finding
⚠️ criticalpolicy claims vs firmware analysis
Samsung told customers their voice data was encrypted when sent from the TV. Security researchers proved this was a lie — voice recordings were sent without encryption, meaning anyone on the same network could listen to what you said near your TV. A privacy watchdog filed a formal complaint with the FTC over this.

What they claim: Samsung's privacy policy states it uses encryption to secure consumers' personal information and protect data in transit.

What we found: EPIC's 2015 FTC complaint documented that Samsung transmitted voice recordings from SmartTV voice recognition to Nuance Communications without encryption. Security researchers independently confirmed they could decode the voice audio in transit, enabling eavesdropping on conversations in users' homes. Samsung's privacy policy explicitly claimed encryption was used, which was demonstrably false.

Honesty 4/4 EXTREME 1 finding
⚡ highpolicy claims vs regulatory findings
Samsung says you can easily control what data your TV collects. But the Texas Attorney General found Samsung's privacy settings were deliberately confusing and hard to find — you have to dig through five menus to turn off screen tracking. Samsung was forced to rewrite its privacy prompts as part of the settlement.

What they claim: Samsung's privacy policy states users can control data collection through settings and make informed decisions about their data.

What we found: Texas AG Paxton's December 2025 lawsuit specifically alleged that Samsung's privacy prompts and consent dialogs were NOT clear or conspicuous, preventing consumers from making informed decisions. The February 2026 settlement required Samsung to "rewrite its on-screen privacy prompts and consent screens" to be clear and conspicuous. The $46M class action similarly alleged Samsung collected data "without proper consent." The ACR opt-out is buried under Settings > Support > Terms & Privacy > Privacy Choices > Viewing Information Services — five menu levels deep.

What happened to real people
Documented incidents involving Samsung products and user data.
Lapsus$ stole 190GB of Samsung source code including biometric unlock algorithms and bootloader source. Potentially compromises security of every Galaxy device. [source]
What your data is worth to governments
Jurisdiction: KR (Korean National Intelligence Service Act).
Documented: Lapsus$ stole 190GB of Samsung source code including biometric unlock algorithms and bootloader source. Potentially compromises security of every Galaxy device.
Sources