Smart TVs Target Residential Proxy Apps

Photo Image
AI-generated illustration

Samsung Electronics and LG Electronics are moving to block “residential proxy” features embedded in smart TV applications after finding a large number of software development kits (SDKs) that could allow unauthorized third parties to use TVs as internet relay points.

According to industry sources, Samsung and LG have been successively blocking smart TV apps containing residential proxy SDKs.

A residential proxy service routes internet traffic through ordinary household internet connections, effectively using them like private servers. Apps may appear to be harmless games, screensavers, or file utilities, but they can be exploited to let third parties use a customer's home internet connection as a gateway.

Security industry sources say apps with these features typically ask users during installation whether they prefer to watch ads or use the app without ads in exchange for sharing their TV's network resources. Choosing the ad-free option can be treated as consent to provide that network access.

Cybersecurity firm Spur found residential proxy SDKs in more than 42% of LG smart TV apps running webOS and more than 26.5% of Samsung TV apps running the Tizen operating system.

LG Electronics has been working with developers since this month to remove proxy capabilities from smart TV apps. The company plans to discontinue apps that do not remove the option and to tighten its app-review process.

Samsung began taking similar action early last month, blocking third-party proxy SDKs in smart TV apps worldwide, including in South Korea, from accessing, collecting, or storing TV-related personal information. The company is also preparing platform policies that would ban residential proxy SDKs outright.

Proxy technology can serve legitimate purposes, including ad verification and market research. But when it is embedded without meaningful user consent, it can create major security risks. If someone connects to the internet through a user's IP address, that household connection could become associated with hacking, illegal downloads, or other criminal activity. Connected devices—including smartphones, PCs, and routers—could also be exposed to attack.

The issue has highlighted a weakness in a business model in which app developers earn revenue by leasing users' internet connections to proxy providers instead of relying on advertising income. Smart TVs are particularly vulnerable because they are not typically viewed as computers and can therefore fall outside routine security checks.

Experts advise users to review app permissions before installation and delete apps they no longer use, steps that can substantially reduce the risk. They also warn that the risk may increase when family members, including minors, agree to requests without fully understanding their implications.

“Configuring a router firewall to block unnecessary external connections from a TV is another option,” a security industry source said. “Users should make a habit of reviewing smart TV app permissions as carefully as they would on a smartphone.”

· This article was translated using AI and was published after final review by the reporter.