42% of LG smart TV apps sell your internet connection to strangers: LG says no more

LG Electronics says it is working with developers to strip residential proxy functionality from apps on its webOS smart TV platform, and will suspend any app that does not comply. The move comes after security researchers found that 42% of scanned LG smart TV apps and 26.5% of Samsung apps contained residential proxy software development kits (SDKs) that let third parties route traffic through a user’s home internet connection.
Researchers at threat intelligence firm Spur scanned 6,038 apps across the LG and Samsung TV stores and identified 2,058 containing proxy SDKs, Brian Krebs reported. The figures prompted LG to publicly threaten enforcement against developers who refuse to remove the proxy option.
What did Spur find inside smart TV apps?
Spur’s scan covered apps distributed through both LG’s webOS store and Samsung’s Tizen store. Across the combined pool of 6,038 apps, 2,058 included proxy SDKs that could sell or lease a household’s IP address to outside parties. The breakdown by platform was uneven:
- Over 42% of LG webOS apps contained residential proxy functionality.
- 26.5% of Samsung Tizen apps contained the same functionality.
Spur researchers described the apps as “laced with proxies,” noting that users may never realize their home connection is being resold. Many of the affected titles are low-effort utilities such as fish tank screensavers, clocks, solitaire, casual games, and puppy videos. “On screen, it’s a relaxing fish tank. Or a clock. Or solitaire. Or puppies. Under the hood, it is a residential proxy: software that can send other people’s internet traffic out through your living room,” Spur wrote.
What did LG say it will do?
According to Krebs on Security, LG’s Senior Vice President John Taylor stated: “LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform. If this option is not removed, these apps will be suspended.” LG framed the proxy behavior as outside the intended use of a smart TV and positioned the suspensions as an enforcement action against misuse of the platform.
LG’s published developer documentation, the Privacy Guideline on webOS TV, already instructs developers to follow “Privacy by Design” and “Secure by Design” principles, including requesting only the least privilege necessary for an app to function. As of publication, the guideline did not contain any explicit reference to residential proxy functionality.
How do users end up consenting to a proxy node?
Spur found that consent flows through generic prompts offering only “agree” or “dismiss” buttons, with no clear explanation of what the user is signing away. Some apps go further, offering users a choice between playing a game with ads or playing ad-free while letting the app use the TV’s internet connection for “web indexing.” The prompts typically explain that the user’s IP address and free resources will be used “to download public web data from the internet.”
Once a user clicks agree, the proxy component can keep running after the app is closed and can continue monetizing the connection for as long as the app remains installed. “Most people do not have a working mental model for what it means to sell access to their residential IP address,” Spur’s researchers wrote.
The risk extends beyond a borrowed IP. Spur warned: “If the proxy provider decides to allow requests to private or local addresses, or if their filtering fails, that TV becomes a foothold for reaching things that were never meant to be exposed to the internet: router admin panels, NAS devices, printers, cameras, developer machines, and other apps listening on local ports.” Smart TVs make ideal hosts because they remain powered on continuously with no battery or cellular data costs to flag suspicious activity.
Which proxy SDK dominates the apps?
Spur traced most proxy-flagged apps to a small number of vendors. The most common SDK identified was Bright SDK from Bright Data, found in 367 of the proxy-flagged apps. Bright Data pushed back on the characterization, arguing that consent is what separates a legitimate network from a malicious one. The company stated: “Bright Data built this framework for consented networks that are intentionally discoverable and therefore accountable. Our practices are scrutinized by independent auditors and security companies.”
How serious is the broader residential proxy problem?
Residential proxy services have legitimate uses, including ad verification, SEO monitoring, market research, and brand protection, and responsible providers say they require explicit user permission. But criminal abuse is well documented. Just weeks before the Spur report, Google and the FBI disrupted a residential proxy botnet called NetNut that hijacked more than 2 million consumer devices, including smart TVs and streaming boxes, for covert cybercrime and espionage. Earlier in the year, another operation called IPIDEA was taken down.
Amazon and Roku have already banned proxy SDKs from their app ecosystems. Spur has called on LG and Samsung to follow suit, framing the current behavior as a category of platform misuse rather than a single-vendor problem.
FAQ
What is a residential proxy?
A residential proxy is a service that routes internet traffic through a real home internet connection, using that household’s IP address to make requests appear as if they come from an ordinary consumer. Legitimate uses include ad verification and market research, but the same setup can be abused for cybercrime, and apps on smart TVs can quietly enroll a user’s TV into such a network.
Why is LG suspending smart TV apps?
LG told Brian Krebs it is working with developers to remove residential proxy options from webOS apps and will suspend any app that does not comply. LG said turning a TV into a proxy node is not the intended use of a smart TV, and the action follows a Spur study that found proxy SDKs in 42% of scanned LG apps and 26.5% of scanned Samsung apps.
Which proxy SDK was found most often in LG and Samsung TV apps?
According to Spur’s research, Bright SDK from Bright Data was the most common proxy SDK, appearing in 367 of the proxy-flagged apps scanned. Bright Data said its framework is designed for consented, discoverable networks and is reviewed by independent auditors.
This article summarizes reporting from cybernews.com.