We don't really have physical access to it - in the sense that on your desktop computer you can boot off a usb drive and reinstall the OS. There is no way you can boot your TV off external media. So you have to hack the existing OS while running it.
The way rooting working on a TV is that you run some javascript in the TV browser that targets some vulnerability in the browser/OS to run some code that then gives you a way in. Or if it has a USB port (to watch videos off a usb drive), you play a specifically crafted video that targets some vulnerability in the media players, to again install some program that then lets you do more serious changes to the OS.
The thing stopped being so needy when I neutered its internet access. Maybe it’s still exfiltrating data but at least it has stopped making me anxious that I may need to consult a civil rights lawyer every time I saw their EULA.
Not that I've done it, I don't get enough value out of it to justify the hassle or the privacy intrusion.