Jul 26, 2026 · AI News

LG to suspend smart TV apps that turn sets into residential proxy nodes

LG smart TV in living room showing fish tank screensaver during proxy network incident

LG Electronics has told developers that it will suspend any webOS app that turns an LG smart TV into a residential proxy node, according to a report by Brian Krebs on Krebs on Security. The warning follows research from threat intelligence firm Spur showing that 42% of LG smart TV apps and 26.5% of Samsung apps contained residential proxy software development kits (SDKs), tools that let strangers route internet traffic through a viewer’s home connection.

What the research found

Researchers at Spur scanned 6,038 apps across the LG and Samsung smart TV stores and found 2,058 containing proxy SDKs. Over 42% of LG webOS apps included the proxy functionality, while 26.5% of Samsung Tizen apps did the same. Apps flagged included screensavers described as a fish tank, a clock, solitaire, and puppies, plus low-value games and utilities that researchers said often function as wrappers around a proxy SDK.

Spur’s report described how the apps behave in practice: “On screen, it’s a relaxing fish tank. Or a clock. Or solitaire. Or puppies. Under the hood, it is a residential proxy: software that can send other people’s internet traffic out through your living room.”

How does a smart TV become a proxy node?

When a user installs an app or game that bundles a proxy SDK, the app typically displays a single consent form with two buttons, agree or dismiss. According to Spur, the prompts frequently state that the proxy can keep running after the app is closed, and some apps force users to choose between playing a game such as Pac-Man with ads, or playing ad-free in exchange for letting the app use the TV’s internet connection to download public web data.

The researchers noted that a one-time agree click can allow the app to keep monetizing the connection for as long as the app stays installed. The viewer’s IP address is then sold to third parties, often without a clear understanding of who is using it or for what purpose. Spur researchers wrote that “most people do not have a working mental model for what it means to sell access to their residential IP address.”

What risks do these proxy apps create?

Residential proxy services are not inherently malicious. Legitimate providers route traffic for businesses conducting ad verification, SEO monitoring, market research, and large-scale data collection, and many claim to require user permission. However, malicious operators also buy access to these networks to disguise their traffic and obscure the origin of attacks.

Spur warned that the danger extends beyond a borrowed IP address. If a proxy provider allows requests to private or local network addresses, or if its filtering fails, the compromised TV can become a foothold for reaching devices on the home network that were never meant to be exposed to the internet, including router admin panels, NAS devices, printers, cameras, and developer machines running on local ports. Smart TVs make ideal hosts because they stay powered on continuously, draw no battery, and generate no obvious usage spike on the home internet bill.

Federal authorities have already moved against large-scale proxy operations. Google and the FBI recently disrupted a residential proxy botnet called NetNut that hijacked more than 2 million consumer devices, including smart TVs and streaming boxes, for covert cybercrime and espionage. Earlier in the year, another residential proxy network called IPIDEA was taken down.

Who is behind the proxy SDKs?

Spur’s research identified that only a handful of firms are responsible for the majority of proxy SDKs found in TV apps. The most flagged vendor was Bright SDK, operated by Bright Data, which appeared in 367 proxy-flagged apps. Bright Data defended its approach, telling Cybernews that consent separates a legitimate network from a malicious one. “Bright Data built this framework for consented networks that are intentionally discoverable and therefore accountable. Our practices are scrutinized by independent auditors and security companies,” the company said.

What is LG actually doing?

According to Krebs on Security, LG conveyed its new position through John Taylor, Senior Vice President at LG. “LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform. If this option is not removed, these apps will be suspended,” the company stated.

Cybernews reported that it could not find any changes or references to residential proxies in LG’s public developer documentation. The existing LG Privacy guideline still directs developers to build apps using “Privacy by Design” and “Secure by Design” approaches, asking them to “ensure that the app requests only the least privilege necessary for its operation.” Amazon and Roku have already banned this type of software from their app stores, and Spur has urged LG and Samsung to follow suit.

FAQ

What is a residential proxy?

A residential proxy is a service that routes internet traffic through real home internet connections, making requests appear to originate from ordinary households. Legitimate uses include ad verification, SEO monitoring, and market research, but the same networks can be abused to hide the origin of attacks or fraud.

How many LG smart TV apps contained proxy SDKs?

Threat intelligence firm Spur found that 42% of LG webOS apps and 26.5% of Samsung Tizen apps contained residential proxy SDKs, out of 6,038 apps scanned across both stores.

What is LG doing about proxy apps on its smart TVs?

LG Electronics told developers through Senior Vice President John Taylor that it is working with them to remove residential proxy options from webOS apps, and that apps which do not comply will be suspended.


This article summarizes reporting from cybernews.com.