Samsung is banning smart TV apps that contain software capable of routing strangers’ internet traffic through users’ home connections, following security research published on Monday by Norwegian cybersecurity firm Mnemonic.
The research, conducted by Mnemonic offensive security consultant Harrison Sand, found that several popular apps on Samsung’s Tizen-based smart TV platform included residential proxy SDKs that could turn a television into an exit node for outside web traffic. One of the apps was a Pac-Man game that Samsung had featured in its “Editor’s Choice” section, according to the report.
Residential proxy networks, or resproxies, funnel third-party web traffic through ordinary home and office internet connections. While not inherently illegal,some are used to evade censorship or to scrape public data for AI training,cybersecurity firms have increasingly linked them to cybercrime, data breaches, and attacks that are harder to detect because the traffic appears to originate from residential addresses.
Sand rooted a Samsung smart TV to monitor all network traffic flowing in and out of the device. He found that the Pac-Man app loaded resproxy code from Bright Data, an Israel-based company that operates a network of millions of residential connections. The code does not activate immediately; it remains dormant until the user accepts a consent screen, after which it runs in the background until the app is deleted.
In a blog post accompanying the research, Mnemonic noted that the distance between an “Editor’s Choice” game and a proxy exit node in a living room is “one server-side configuration change and one button press from whoever happens to be holding the remote.” Sand also warned that a “simple code change on a web server” could instantly activate the resproxy code on a large number of installed devices, effectively conscripting them into a botnet.
By inspecting the network traffic routed through his test television, Sand observed what appeared to be large-scale scraping of LinkedIn profiles and the collection of data for AI model training. He noted that he could see only a small fraction of the total traffic flowing across Bright Data’s network.
After TechCrunch contacted Samsung for comment, the company said in a statement that it had already restricted new app registrations incorporating proxy functionality and was implementing “strict platform-wide developer policies explicitly banning residential proxy SDKs.” A spokesperson added that Samsung is “working to identify and remove all apps currently available in our store that contain these components.”
The move follows a similar announcement from LG last month. In July, LG Senior Vice President John Taylor told KrebsOnSecurity that the company would suspend apps on its webOS platform that include residential proxy SDKs, after separate research from security firm Spur found that roughly 42 percent of apps on LG’s app store and more than 25 percent of apps on Samsung’s store contained such components. Bright Data accounted for a majority of the proxy SDKs across both platforms, Spur reported.
Bright Data, which did not respond to TechCrunch’s request for comment, has previously stated that its network operates on user consent and that customers are vetted. In a statement to KrebsOnSecurity in July, the company said its practices had undergone an independent audit by PwC and that it remains committed to “an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain.”
Mnemonic’s research also highlighted a structural challenge for app store operators: many smart TV apps are thin shells that load content from remote servers, meaning what is reviewed during certification may not match what is delivered to users after installation. “What was reviewed is not necessarily what is running,” Sand wrote.
Download the featured image: featured-image-samsung-smart-tv-proxy