Samsung and LG ban smart TV apps using residential proxy SDKs
Samsung and LG have moved to ban smart TV apps that utilize residential proxy SDKs following security research by Mnemonic. The research found that apps, including some featured in app stores, were enlisting devices as exit nodes in proxy networks used for large-scale data scraping and potential cybercrime.
Key Takeaways
- Samsung is implementing platform-wide policies to explicitly ban residential proxy SDKs and remove existing apps.
- A featured 'Editor's Choice' Pac-Man game was found to contain dormant proxy code that activates upon user consent.
- LG recently suspended similar apps after findings that 42% of its app store offerings included proxy functionality.
- The SDKs allow outsiders to route encrypted traffic through home connections, masking the origin of scraping or attacks.
Why It Matters
The discovery of proxy SDKs in high-profile, manufacturer-endorsed apps exposes a critical breakdown in the smart TV app vetting process. For the streaming industry, this highlights a growing security risk where hardware becomes a silent participant in botnets used for credential stuffing or AI data harvesting. The immediate fallout involves a massive cleanup of the Tizen and webOS app stores, but the broader implication is a shift toward more stringent, mobile-like app permissions for TVs. Stakeholders should watch for new developer transparency mandates and whether regulators like the FTC classify these bandwidth sharing schemes as deceptive practices given their potential for facilitating cybercrime.
Additional Context
The crackdown follows a surge in the residential proxy market, where providers pay app developers to embed SDKs that monetize unused consumer bandwidth. While marketed as legitimate tools for ad verification and market research, security firms have increasingly linked these networks to malicious activity. Per Krebs on Security in July 2026, research by Spur found that over 25% of Samsung Tizen apps and 42% of LG webOS apps were 'laced' with this software, often disguised in low-quality games or utility tools. This high prevalence suggests that proxy operators have successfully pivoted to the smart TV ecosystem to obtain 'clean' residential IP addresses that are less likely to be blocked by anti-scraping filters than datacenter IPs.
Technically, these SDKs can be highly invasive. According to a June 2026 analysis by The Hacker News, some variations of these tools can bypass active VPNs on the device level and continue running in the background even after the host app is closed. This behavior has drawn comparisons to 'proxyware' or botnets, particularly as the demand for residential IPs grows for training large language models. Bright Data, a prominent player in this space, has previously pitched these SDKs to streaming operators as an alternative monetization strategy to advertising, claiming the networks only collect public web data anonymously.
Regulatory scrutiny is also intensifying. As of May 2026, twenty U.S. states have enacted comprehensive privacy laws, with several state attorneys general focusing on the lack of clear disclosure in SDK-based data collection. Per a February 2026 report from the Future of Privacy Forum, federal and state regulators are increasingly targeting first-party platform owners for failing to police third-party SDKs that collect or share user resources without explicit, unbundled consent. This suggests that Samsung and LG's sudden bans may be a preemptive move to avoid liability under evolving state-level consumer protection frameworks.
Read full article at techcrunch.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source