

The first step is buying devices from reputable vendors and trustworthy resellers to minimize the likelihood of malware being pre-loaded from the factory or while in transit.
Given the size I suspect this is also a common attack vector.
Also,
Android TV devices should have their remote access features disabled if not needed, while taking them offline when not used is also an effective strategy.
Is this a thing? Why would a TV have remote access features?
As a quick test, 300 words of “Lorem Ipsum” compresses down to about 900 bytes (using gzip).
So I’ve got about 300 or so words worth of storage, probably more of I get clever.
Now I can’t natively decode gzip, but the header is unique enough that I’ll figure out how to decode it pretty quickly.
That’s more than enough to explain to myself what’s going on, what I’ve tried and anything else I’d want to know.
If we add other people then that’s basically infinite storage.