Samsung joins LG in banning residential proxy SDKs on smart TVs
Samsung and LG have moved to ban residential proxy SDKs across their smart TV platforms following research by Mnemonic and Spur. The initiative seeks to prevent apps from converting consumer televisions into unauthorized exit nodes for data scraping, a practice that poses security risks and interferes with advertising fraud detection.
Key Takeaways
- Samsung and LG are removing residential proxy SDKs that convert smart TVs into exit nodes for commercial data scraping.
- Security firm Spur identified proxy code in 42.5% of LG webOS apps and 26.9% of Samsung Tizen apps.
- Mnemonic traced Bright Data proxy code inside a featured Pac-Man game promoted in Samsung's Editor's Choice section.
- The SDKs allow encrypted traffic to persist in the background even after the host application is closed.
Why It Matters
The presence of residential proxies on smart TVs creates a dual risk of security vulnerabilities and advertising measurement degradation. By routing automated traffic through household IP addresses, these SDKs complicate invalid traffic (IVT) detection for verification vendors like DoubleVerify and HUMAN Security, who rely on IP reputation to distinguish humans from bots. For Samsung and LG, which are both expanding their programmatic CTV advertising businesses, purging these SDKs is necessary to protect the integrity of their first-party audience signals. Watch for whether Amazon and Roku adopt similar platform-wide developer policy enforcements to address these specific types of background connectivity risks.
Additional Context
The crackdown on residential proxy SDKs aligns with a broader push for transparent data practices in the smart TV ecosystem. Per state filings from May 2026, Samsung and LG both reached settlements with the Texas Attorney General regarding the use of Automatic Content Recognition (ACR) technology. These agreements require the manufacturers to replace buried settings with prominent opt-in disclosures, as the state alleged prior setup flows relied on dark patterns to capture viewing data without informed consent. This regulatory pressure on 'passive' data collection reflects growing scrutiny of how hardware manufacturers monetize background device activity.
From a security perspective, the threat extends beyond privacy to network integrity. According to reports from KrebsOnSecurity in January 2026, botnets like Kimwolf have already targeted more than two million Android-based TV devices by exploiting residential proxy networks to move laterally within home networks. Security researchers at Bitdefender estimated earlier in 2025 that smart TVs account for roughly 21% of security flaws found in the average smart home. These findings have forced manufacturers to re-evaluate their developer vetting processes, as thin-shell apps can bypass static store reviews by loading proxy behaviors from remote servers after installation.
In the advertising sector, the use of residential IPs for scraping and bot activity is a significant financial drain. Analysis from Truthset in July 2026 estimated that inaccurate identity signals, often masked by residential proxies, will waste approximately $7.4 billion in U.S. CTV programmatic spend this year. As DoubleVerify reported a 140% surge in CTV fraud schemes in early 2026, the industry is shifting toward device-level identifiers rather than IP addresses to validate real households. The removal of proxy SDKs is a foundational step in ensuring that residential IPs remain a high-trust signal for premium video buyers.
Read full article at ppc.land
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source