
Samsung is banning smart TV apps that allow outside parties to route internet traffic through customers’ home or office connections. The policy change follows research from Norwegian cybersecurity company Mnemonic, which found residential proxy software inside several apps available through Samsung’s television app store.
Some developers claim the affected apps have been installed on hundreds of millions of televisions. One example was a basic Pac-Man game that Samsung had featured in the Editor’s Choice section of its app store.
Apps Could Turn TVs Into Proxy Exit Nodes
Residential proxy software allows a third party to send web traffic through an ordinary household internet connection. Once activated, the television operates as an exit node, making the outside traffic appear to originate from the TV owner’s network.
These networks have legitimate uses, including avoiding censorship and collecting publicly available online data. However, cybersecurity companies have also linked them to scraping, cyberattacks and other activity where operators seek to conceal their actual locations.
Mnemonic researcher Harrison Sand rooted a Samsung television to examine its internal software and network activity. He found that the Pac-Man app contained proxy code supplied by Israeli company Bright Data.
The code remained inactive until a user accepted a consent screen. Once approved, it continued operating in the background until the app was deleted, even when the game was no longer open.
Remote Content Complicates App Reviews
Many Samsung television apps contain only a small amount of local code and load their main content from external websites. This structure means Samsung may review the code initially submitted by a developer without seeing everything that later runs inside the app.
Sand warned that developers could change code hosted on an external server after an app had passed review. A remote change could therefore activate proxy functionality across a large number of installed televisions without submitting an updated app.
During testing, Sand observed traffic that appeared connected to large-scale LinkedIn profile scraping and AI training data collection. He said the activity represented only a small sample of the traffic passing through Bright Data’s network.
Samsung Begins Removing Proxy-Enabled Apps
Samsung told TechCrunch that it had restricted new app registrations containing residential proxy functionality. The company said it was introducing stricter developer policies and identifying existing apps that should be removed.
Samsung’s official app registration rules now state that residential proxy functionality, including software such as Bright Data’s development kit, is not permitted.
The action follows a similar decision by LG, which said it would suspend smart TV apps containing proxy software. Earlier research found residential proxy components in 2,058 of 6,038 Samsung and LG television apps examined.
Featured image credits: Kārlis Dambrāns via Flickr
For more stories like it, click the +Follow button at the top of this page to follow us.
