Smart Glasses Could Be Watching You Back: Meta App Demands 70 Permissions in Privacy Test

The findings highlight mounting security concerns for both wearers and bystanders as regulators race to catch up

Ray-Ban Meta Glasses Headache Causes
New research exposes severe privacy flaws across the smart eyewear market, revealing that cheap imports can be hijacked by strangers and most major brands fail to secure recording indicator lights Gemini

AI smart glasses could pose a privacy risk to the people wearing them, not just those caught in their cameras, with Meta's companion app requesting 70 permissions in a new analysis of seven brands.

A fresh analysis by Cybernews found that Meta's app requested the highest number of permissions among the smart-glasses apps examined, including 18 classified as 'dangerous' by Android. The findings suggest that privacy concerns surrounding AI eyewear extend beyond covert filming, with companion apps also requesting access to sensitive phone functions and data.

The test examined seven lines of AI smart glasses and their companion apps, including Meta's eyewear and products from Chinese manufacturers such as Rokid, RayNeo and INMO, as well as Solos, Even Realities and Halliday.

The analysis, which used data provided by privacy audit group Exodus Privacy, also examined trackers, recording-light protections, AI processing and data-retention policies.

Meta App Requests 70 Permissions

To unlock their full range of features, the tested AI glasses connect to companion smartphone apps, which can request access to functions and data on the user's phone.

Meta's app recorded the highest number of permissions at 70, followed by Even Realities at 61, Solos AirGO at 55 and Hi Rokid at 53. Halliday had the lowest total at 32.

Meta also recorded the highest number of permissions classified as 'dangerous' by Android, with 18, accounting for about 26 per cent of its total. These included permissions associated with audio recording, text messages and external storage.

Android's 'dangerous' classification does not mean an app is malicious. Instead, it refers to permissions that can provide access to sensitive data or device functions and therefore require explicit approval from the user.

Halliday had 12 such permissions, representing nearly 38 per cent of its total requests.

AI Data Goes to the Cloud

The privacy concerns extend beyond what permissions an app requests on a smartphone.

Cybernews found that all seven apps process their AI features in the cloud, with none of the tested glasses running core functions such as voice, translation or image analysis entirely on the device.

That means some information captured or generated while using AI features may need to be sent to the cloud for processing, raising questions about how sensitive recordings and other user data are handled.

The analysis also found that five of the seven devices did not clearly specify how long collected data would be retained.

Even Realities was the most explicit, stating that voice captures are deleted immediately, while Meta caps some data at between 30 days and a year, depending on the type of data.

Only Meta, Rokid and Even Realities were found to provide privacy documentation specifically tailored to their devices. INMO and Solos had dedicated sections within broader company policies, while RayNeo and Halliday relied on generic company-wide policies without specific mention of their glasses.

Some Apps Contain Multiple Trackers

The companion apps also differed significantly in the number of embedded trackers they contained.

INMO Global and Solos AirGO each had six detected trackers, the highest number in the test. INMO's app included Huawei tools linked to functions such as location, advertising and analytics, while Solos AirGO contained three separate Meta/Facebook trackers, alongside Google Firebase Analytics and Crashlytics.

Meta's app had one detected tool, Facebook Flipper, which Cybernews identified as an internal debugging tool rather than an external advertising or analytics SDK.

At the other end of the scale, Hi Rokid was the only app in the test with no detected trackers.

The findings do not establish that the trackers were being used maliciously, but they highlight how differently the companion apps approach data collection and third-party software.

Recording Lights Face Privacy Test

The privacy concerns are not limited to information collected from the people wearing the glasses. The devices can also raise questions about people who happen to be in front of their cameras.

Cybernews evaluated the products against nine privacy benchmarks inspired by Apple's approach to privacy, including camera indicators, on-device processing and data retention.

Only Meta and Rokid had a confirmed response when their recording indicators were covered. RayNeo and Solos did not have equivalent protections identified in the test.

Meta introduced a software update in late August that stops the device from recording when the warning light is covered, amid growing backlash over non-consensual videos filmed with Meta glasses.

Facial Recognition Raises Future Concerns

The latest findings come amid wider scrutiny of the security and privacy implications of AI-enabled eyewear.

An investigation by Australia's ABC News into inexpensive smart glasses sold through platforms including Temu also found that outsiders could take control of some devices, raising concerns about the security of the glasses and their users' data.

Facial recognition represents another potential privacy concern, although Cybernews did not find active facial-recognition capabilities in any of the seven products it tested.

WIRED previously reported that Meta's companion app contained dormant code for an unreleased facial-recognition system known as NameTag.

Meta described the technology as an 'ongoing exploration', saying that nothing had been released to consumers and that no final decision had been made on whether to deploy it.

WIRED later reported that Meta removed the NameTag code from the latest version of its companion app after the report was published.

For now, the Cybernews findings point to a more immediate set of privacy questions: how much access AI-glasses apps request, what data is sent to the cloud, how long that information is retained and how effectively the devices protect people from unwanted recording.