Smart TV Apps Covertly Convert Devices into AI Scraping Proxies
Free apps on Samsung, LG, and Roku smart TVs are reportedly deploying an SDK from Bright Data to convert millions of devices into residential proxies for web-scraping, often without explicit user consent. This practice routes third-party web-scraping traffic, potentially for AI training data, through users' internet connections, raising significant privacy and security concerns for CTV users and network operators. Researchers from Include Security identified the Bright Data SDK, its configuration, and provided technical details for network blocking.
Key Takeaways
- Bright Data's SDK routes third-party web-scraping traffic through user internet connections, with default monthly bandwidth capped at 200 GB per device.
- Connected TVs are targeted for proxy use due to constant power, Wi-Fi connectivity, 24/7 standby, minimal oversight, and infrequent user attendance.
- The SDK's configuration allows devices to relay traffic even when users are actively watching or on calls, indicated by `ignore_screen_on: true` and `ignore_on_call: true` flags.
- Partner manifest exposed by Bright Data includes PlayWorks Digital (250M TV households), CloudTV (125+ TV brands), Viber Media (250M-820M MAU), and Moonfrog Labs (~10M MAU).
- The SDK bypasses user-configured VPNs by binding data traffic directly to physical Wi-Fi or cellular interfaces using Apple's `NWParameters.requiredInterface` API.
Why It Matters
This practice highlights a growing concern over device exploitation for AI training data, impacting user privacy and network security within the streaming ecosystem. The covert nature of the SDK's operation, particularly its ability to bypass VPNs and operate during active use, introduces a novel vector for data exfiltration and bandwidth consumption on residential networks. Industry players should assess their app ecosystems for similar embedded SDKs and implement stricter oversight on third-party integrations to protect consumer trust and network integrity. All actors in the streaming value chain should reassess device security policies and user consent mechanisms for data collection.
Additional Context
The practice of embedding proxy SDKs in free apps has faced increasing scrutiny beyond the current report. The Verge noted in February 2026 that Bright Data offers app publishers an alternative monetization model: fewer ads or no fees in exchange for integrating its SDK and allowing smart TVs to join its proxy network. Bright Data claims its network operates on consensual individual participation with a 'two-click' opt-out, but researchers and observers like The Verge's Janko Roettgers question the clarity of this consent, especially given the technical complexities involved with smart TV remote navigation. Google has reportedly acted against proxy SDKs running in the background, updating its policies to limit proxy services to apps where it's the 'primary, user-facing core purpose' (The Verge). Amazon also added a provision to its developer policies banning 'apps that facilitate proxy services to third parties', and Roku bars developers from using Bright Data's SDK and similar services. Due to these restrictions, Bright Data no longer supports Roku, Android TV, or Fire TV, though Samsung's Tizen OS and LG's webOS remain listed as supported smart TV platforms (The Verge).
Read full article at cybersecuritynews.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source