anagnorisis.cloudSign in

← Hourlies

Hourly ·

LG Cracks Down on Smart TV Apps That Turn Living Rooms into Proxy Servers

LG will suspend webOS apps embedding residential proxy SDKs after Spur research found 42% of smart TV apps secretly rent out home internet connections.

LG Cracks Down on Smart TV Apps That Turn Living Rooms into Proxy Servers

The home appliance giant LG Electronics USA said it plans to suspend any apps built for its smart TVs that turn televisions into always-on residential proxy nodes. The move comes after security researchers found that more than 42 percent of apps on LG's webOS platform include software development kits that route third-party internet traffic through users' TVs, often without meaningful disclosure.

Security firm Spur scanned 6,038 LG and Samsung smart TV apps and discovered 2,058 contained residential proxy SDKs. The problem spans both major smart TV platforms: 42 percent of LG webOS apps and over a quarter of Samsung Tizen apps had proxy components buried inside. Many of the affected apps were thin shovelware games, screensavers, and utility apps seemingly built as wrappers for the proxy SDK — the residential IP address was the real product.

LG Senior Vice President John Taylor confirmed the company is working with developers to remove the proxy option. "A residential proxy network is not an intended use for LG smart TVs," Taylor told KrebsOnSecurity. Developers that fail to comply will find their apps suspended.

The most prevalent proxy provider was Bright Data, which accounted for the majority of flagged apps across both platforms. Other providers include Massive and Honeygain, a subsidiary of Oxylabs. All three companies told Spur they enforce know-your-customer processes and traffic filtering, but researchers noted that a one-time consent prompt buried in a TV app "is not a substitute for meaningful transparency, ongoing control, and platform oversight."

The security implications go beyond bandwidth theft. Once a TV app acts as a proxy, it sits inside the user's home network. If filtering fails or is bypassed, that foothold can expose router admin panels, NAS devices, cameras, and other local network devices. Earlier this year, KrebsOnSecurity reported on the Kimwolf botnet, which abused residential proxy networks to tunnel into local networks behind proxy endpoints.

Notably, other TV platforms have already drawn a line. Amazon Fire TV explicitly bans apps that facilitate proxy services. Roku has reportedly blocked proxy SDKs. LG and Samsung had not drawn an equivalent public line — until now. LG said its review is "well underway" and pledged to strengthen its evaluation process going forward.

Sources: Krebs on Security, Spur

More Hourlies Stories

Content on Anagnorisis is summarized, paraphrased, and editorialized from publicly available sources for length and clarity. Original sources are linked where available. All trademarks belong to their respective owners.

More from Anagnorisis