LG bans residential proxy SDKs after 42% of apps found compromised
LG Electronics USA is mandating the removal of residential proxy SDKs from applications on its webOS platform to prevent smart TVs from being used as traffic nodes. The decision follows research from security firm Spur, which identified these proxy components in 42% of LG smart TV apps, raising significant security and transparency concerns.
Key Takeaways
- Security firm Spur identified proxy SDKs in 42% of LG webOS apps and 27% of Samsung Tizen apps.
- Bright Data was named the dominant provider of these proxy kits across both smart TV platforms.
- LG Senior VP John Taylor confirmed the company is currently reviewing app submissions for non-compliance.
- Residential proxy services allow paying customers to use consumer IP addresses to mask web-scraping and data harvesting.
Why It Matters
The crackdown signals a tightening of smart TV ecosystem security as platforms move to block background traffic routing that bypasses traditional network monitoring. While these SDKs offer developers a monetization alternative to advertising, they turn household devices into exit nodes for unknown third-party traffic, creating significant privacy and liability risks for consumers. For hardware manufacturers, the prevalence of such kits highlights a critical oversight gap in automated app store vetting processes. Watch specifically for Samsung's response to the 2,000+ proxy-embedded apps recently identified across the Tizen and webOS stores and whether strict API restrictions follow.
Additional Context
The move by LG aligns with a broader trend of smart TV platform owners restricting background proxy behavior to protect network integrity. Per recent reporting from The Verge in July 2026, rivals including Google, Amazon, and Roku have already enacted policies to block residential proxy SDKs like those from Bright Data. Those platforms now explicitly prohibit apps from facilitating third-party proxy services in their developer guidelines, a regulatory stance Samsung and LG are only now beginning to adopt. Bright Data currently markets a network of over 150 million residential IPs, often utilized by AI firms for large-scale web scraping.
This security pivot also coincides with mounting legal pressure over smart TV data management. In May 2026, per Fox 26 Houston, LG Electronics USA reached a settlement with the Texas Attorney General following allegations that its Automated Content Recognition (ACR) technology collected viewing habits without sufficiently informed consent. The settlement requires LG to provide clear pop-up disclosures and explicit opt-out controls for data collection. Similar litigation reached a settlement with Samsung in March 2026 regarding its own tracking software, which reportedly captured screen telemetry every 500 milliseconds.
Furthermore, independent researchers at Include Security documented in June 2026 that these proxy SDKs often maintain persistent WebSocket connections to external infrastructure. These connections transmit device telemetry including battery levels, CPU usage, and network identity to the proxy provider. While providers like Bright Data cite external audits by firms like PwC and robust 'know your customer' vetting processes, researchers argue that a one-time consent screen on a television remote is insufficient for turning residential hardware into commercial infrastructure.
Read full article at krebsonsecurity.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source