← Smart TVs
C

Crystal UHD DU7200 (2024)

Notable issues
Samsung · 🇰🇷 South Korea · WiFi + Bluetooth
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
FCC ID: A3LWID210S
Chipset: Samsung Crystal Processor 4K (MediaTek-based)
App: com.samsung.android.oneconnect
Manufacturer: Samsung

⚠️ The bottom line

Samsung told customers their voice data was encrypted when sent from the TV. Security researchers proved this was a lie — voice recordings were sent without encryption, meaning anyone on the same network could listen to what you said near your TV. A privacy watchdog filed a formal complaint with the FTC over this. Samsung points out their TVs don't have a built-in microphone as a privacy feature. But security researchers found that someone nearby can hack the TV remote's microphone via Bluetooth, turning it into a listening device. The "no mic in the TV" claim gives a false sense of security when the remote's mic can be hijacked just as easily.

Legal jurisdiction
🇰🇷 South Korea (headquarters)
PIPA read more →
Strict data protection — fined Google, Meta. But National Intelligence Service has broad surveillance powers
B
Parent company: Samsung
Smart TV voice recording scandal, Korean National Intelligence Service Act
2 structural risks · 12 products →
Spying
4/4 EXTREME
Is someone spying on me?
Data Sharing
3/4 HIGH
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Honesty
4/4 EXTREME
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
13Contradictions
2Critical
7High
4Medium
12Sources
Findings by concern
Spying 4/4 EXTREME 8 findings
⚠️ criticalregulatory findings vs firmware analysis
Samsung points out their TVs don't have a built-in microphone as a privacy feature. But security researchers found that someone nearby can hack the TV remote's microphone via Bluetooth, turning it into a listening device. The "no mic in the TV" claim gives a false sense of security when the remote's mic can be hijacked just as easily.

What they claim: CVE-2022-44636 (Samsung-classified as critical, SVE-2022-50125): Samsung TV smart remote control allows Bluetooth spoofing to enable microphone access. Samsung markets its TVs as not having built-in microphones — the mic is on the remote — framing this as a privacy advantage.

What we found: The remote control's microphone can be hijacked via Bluetooth spoofing (CVE-2022-44636). An attacker within Bluetooth range can spoof the remote pairing process when a user presses a button, gaining unauthorized microphone access. This means the "privacy advantage" of not having a built-in TV mic is undermined — the remote's mic is equally exploitable. Samsung's own security bulletin classified this as critical severity, yet the marketing materials continue to emphasize the absence of a built-in TV microphone.

⚡ highpolicy claims vs firmware analysis
Samsung's privacy policy makes it sound like the TV only tracks which TV shows and channels you watch. But the tracking also captures whatever is on screen when you connect a laptop, game console, or any other device via HDMI. If you use your Samsung TV as a computer monitor, it's taking screenshots of your work too.

What they claim: Samsung's SmartTV privacy supplement describes ACR as collecting information about "channels and networks you watch" and "programs you view" — implying it only tracks broadcast/streaming content on the TV's native apps.

What we found: UCL/UC Davis research (2024) confirmed that Samsung's ACR fingerprints content displayed on ALL inputs, including HDMI. This means content from external devices (gaming consoles, laptops, Blu-ray players) connected via HDMI is also captured and fingerprinted. The $46M class action specifically noted ACR records "content displayed when the TV is used as a computer monitor." The policy language about "channels" and "programs" obscures the true scope of surveillance.

⚡ highapp permissions vs firmware analysis
To control your Samsung TV, you need the SmartThings app, which demands access to your phone calls, camera, microphone, contacts, precise location (even in the background), physical activity tracking, and the ability to see every app on your phone. Most of these have nothing to do with controlling a TV.

What they claim: The Samsung Smart TV is a television — a display device for watching content. It does not make phone calls, track physical activity, or function as a surveillance camera.

What we found: The SmartThings companion app requests 46 permissions including: CALL_PHONE, RECORD_AUDIO, CAMERA, ACCESS_FINE_LOCATION, ACCESS_BACKGROUND_LOCATION, ACTIVITY_RECOGNITION, HIGH_SAMPLING_RATE_SENSORS, READ_CONTACTS, READ_PHONE_NUMBERS, READ_PHONE_STATE, MODIFY_PHONE_STATE, QUERY_ALL_PACKAGES, WRITE_SECURE_SETTINGS, and WRITE_SETTINGS. Many of these permissions have no reasonable connection to controlling a television.

⚡ highfirmware analysis vs policy claims
Samsung sells these TVs as entertainment devices with fancy picture technology. But under the hood, the TV is constantly talking to advertising and tracking servers — taking a screenshot of your screen twice every second. It's really an advertising platform that happens to show you TV, not a TV that happens to show you ads.

What they claim: Samsung markets its Crystal UHD TVs as entertainment devices with "PurColor" and "Crystal Processor 4K" for an enhanced viewing experience.

What we found: The TV's firmware contacts 9+ dedicated endpoints including ACR tracking servers (acr-us-prd.samsungcloud.tv, log-config.samsungacr.com), advertising infrastructure (osb-apps.samsungqbe.com), and Samsung cloud services. The device functions as an advertising platform that also displays content — not the other way around. The ACR system captures screen fingerprints every 500ms across ALL inputs, making the TV fundamentally a surveillance device wrapped in entertainment marketing.

⚡ highmarketing vs regulatory
Your Samsung TV took a screenshot of what you were watching twice every second. Everything on screen — news, banking apps, video calls, private photos — captured and sent to Samsung. Texas sued. Samsung settled. Then Texas sued Sony, LG, Hisense, and TCL for doing the same thing. Your television watches you more closely than you watch it.

What they claim: Samsung describes Smart TV viewing data collection for personalisation

What we found: The Texas Attorney General settled with Samsung over its Automated Content Recognition (ACR) system, which captured screenshots of whatever was on screen every 500 milliseconds — twice per second. Samsung must now obtain express consent before collecting viewing data. Texas also sued Sony, LG, Hisense, and TCL for identical ACR surveillance, with Hisense receiving the first-ever temporary restraining order against a TV maker.

⚫ mediumfirmware analysis vs regulatory findings
Samsung TVs have a built-in web browser, but that browser has serious security holes. If you visit a malicious website on your TV, hackers could take control of the TV itself. Since the TV already has access to everything you watch and your home network, a compromised TV is a much bigger problem than a compromised website on your phone.

What they claim: Samsung Tizen TVs include a built-in web browser based on Chromium/V8, marketed as a feature for internet browsing on the big screen.

What we found: Multiple high-severity vulnerabilities in the TV's browser engine: SVE-2022-50146 through SVE-2022-50152 (V8 JIT compiler bugs enabling remote code execution on 2020-2022 models) and SVE-2023-50069 (XML validation bypass in Chromium). Visiting a malicious website on the TV's browser could allow an attacker to execute arbitrary code on the TV — a device that has ACR access to everything displayed on screen, network access, and (via CVE-2022-44636) potential microphone access through the remote.

⚫ mediumpolicy claims vs regulatory findings
Samsung claims to take security seriously and uses its Knox brand to suggest strong protection. But over the past decade, they've been caught sending voice data unencrypted, tracking viewing habits without consent, having hackable remote microphones, and browser security holes that let hackers in. The "secure" branding doesn't match the track record.

What they claim: Samsung's privacy policy claims data is processed securely and mentions Samsung Knox security for device protection.

What we found: EPIC's 2015 FTC complaint established that Samsung transmitted voice recordings unencrypted to Nuance Communications. The $46M class action found ACR data collected without proper consent. The Texas AG found privacy prompts were misleading. CVE-2022-44636 shows the remote's mic can be hijacked via Bluetooth. V8 JIT bugs (SVE-2022-50146) enable remote code execution via the browser. The pattern across a decade (2015-2026) shows Samsung repeatedly failing to meet its own stated security commitments.

⚫ mediummarketing vs regulatoryPartially addressed
Texas called Samsung Smart TVs "a mass surveillance system" — then sued. Samsung settled in February 2026, agreeing to stop collecting your viewing data without real consent. The old system: one click to opt in, 200 screens to understand what you agreed to. Firmware updates silently turned tracking back on. Samsung had to rewrite its consent screens because a state government said they were designed to trick you.

What they claim: Samsung claims its Smart TVs collect viewing data only with user consent and provide clear privacy controls

What we found: Samsung settled the Texas AG's ACR surveillance lawsuit in February 2026. Texas called Samsung TVs "a mass surveillance system." Samsung agreed to stop collecting viewing data without explicit consent and rewrite privacy consent screens to eliminate dark patterns. The original opt-in required one click during setup; reviewing the privacy implications required navigating over 200 separate screens. Firmware updates could silently re-enable ACR.

Data Sharing 3/4 HIGH 3 findings
⚡ highpolicy claims vs firmware analysis
Samsung says it watches what you view on your TV to give you better recommendations. In reality, the TV takes a screenshot every half second of everything on screen — including content from your gaming console, laptop, or DVD player connected via HDMI — and sends this data to Samsung's advertising servers. Samsung was sued by Texas and paid $46 million in a class action because this data was being sold for advertising, not just used for recommendations.

What they claim: Samsung's SmartTV Supplement states that viewing information is collected "to enhance video content" and provide "customised TV, movie, and other content recommendations." This frames ACR as a helpful recommendation feature.

What we found: Firmware-level ACR system captures screen fingerprints every 500ms and transmits to dedicated ACR servers (acr-us-prd.samsungcloud.tv, acr0.samsungcloudsolution.com, log-config.samsungacr.com). UC Davis/UCL research (IMC 2024) confirmed Samsung transmits up to 2x more ACR data than LG. The $46M class action settlement and Texas AG lawsuit (December 2025) established that this data is monetized for advertising — not merely used for recommendations. Samsung settled with Texas on February 26, 2026, agreeing to halt ACR collection without express consent.

⚡ highmarketing vs third party research
Free apps on your Samsung TV are quietly turning it into a worker bee for AI companies. While you watch Netflix, your TV is being used to scrape websites and collect data to train AI models. The "consent" is hidden in a menu designed for a TV remote — you technically agreed by clicking through screens you didn't read because who reads terms on a television.

What they claim: Samsung promotes smart TVs as entertainment devices for the home

What we found: Free apps on Samsung smart TVs are secretly enrolling devices into commercial residential proxy networks used to scrape web data for AI training. Consent is buried in a TV remote's arrow-key navigation dialog that most users never meaningfully interact with. Millions of living room devices have been conscripted into data collection infrastructure without owners' practical awareness.

⚫ mediumapp permissions vs policy claims
The SmartThings app — which you need to control your Samsung TV — secretly sends your usage data and device information to Microsoft through embedded tracking software. Samsung's privacy policy doesn't mention Microsoft by name, so you'd never know your TV remote app is reporting to Microsoft.

What they claim: Samsung's privacy policy mentions sharing data with "service providers" and "analytics companies" but does not name specific third parties receiving SmartThings app data.

What we found: The SmartThings app (v1.8.21.28) embeds two Microsoft trackers: Microsoft Visual Studio App Center Analytics and Microsoft Visual Studio App Center Crashes (identified via Exodus Privacy report). These trackers send app usage data, crash reports, and device information to Microsoft's servers. Samsung's privacy policy does not specifically name Microsoft as a data recipient, despite the SmartThings app being the primary way users interact with Samsung smart home devices including TVs.

Security 3/4 HIGH 1 finding
⚠️ criticalpolicy claims vs firmware analysis
Samsung told customers their voice data was encrypted when sent from the TV. Security researchers proved this was a lie — voice recordings were sent without encryption, meaning anyone on the same network could listen to what you said near your TV. A privacy watchdog filed a formal complaint with the FTC over this.

What they claim: Samsung's privacy policy states it uses encryption to secure consumers' personal information and protect data in transit.

What we found: EPIC's 2015 FTC complaint documented that Samsung transmitted voice recordings from SmartTV voice recognition to Nuance Communications without encryption. Security researchers independently confirmed they could decode the voice audio in transit, enabling eavesdropping on conversations in users' homes. Samsung's privacy policy explicitly claimed encryption was used, which was demonstrably false.

Honesty 4/4 EXTREME 1 finding
⚡ highpolicy claims vs regulatory findings
Samsung says you can easily control what data your TV collects. But the Texas Attorney General found Samsung's privacy settings were deliberately confusing and hard to find — you have to dig through five menus to turn off screen tracking. Samsung was forced to rewrite its privacy prompts as part of the settlement.

What they claim: Samsung's privacy policy states users can control data collection through settings and make informed decisions about their data.

What we found: Texas AG Paxton's December 2025 lawsuit specifically alleged that Samsung's privacy prompts and consent dialogs were NOT clear or conspicuous, preventing consumers from making informed decisions. The February 2026 settlement required Samsung to "rewrite its on-screen privacy prompts and consent screens" to be clear and conspicuous. The $46M class action similarly alleged Samsung collected data "without proper consent." The ACR opt-out is buried under Settings > Support > Terms & Privacy > Privacy Choices > Viewing Information Services — five menu levels deep.

What happened to real people
Documented incidents involving Samsung products and user data.
Lapsus$ stole 190GB of Samsung source code including biometric unlock algorithms and bootloader source. Potentially compromises security of every Galaxy device. [source]
What your data is worth to governments
Jurisdiction: KR (Korean National Intelligence Service Act).
Documented: Lapsus$ stole 190GB of Samsung source code including biometric unlock algorithms and bootloader source. Potentially compromises security of every Galaxy device.
Sources