Security research reports that certain Samsung smart TV applications include code that can route other parties’ web traffic through the home internet connections of the TVs where the apps are installed. Researchers say this behavior effectively turns affected devices into “residential proxies,” which can function as always-on exit nodes even when an app is not actively open. The investigation by Mnemonic describes how many affected apps appear to be simple shells that load content from external servers; the code visible during review may not reflect what actually runs, which can make problematic behavior harder to spot during app store vetting.
Samsung responded after TechCrunch contacted the company for comment. Samsung says it is banning apps that share users’ internet connections and is removing apps that include the relevant proxy functionality. The company also says it has restricted new app registrations that incorporate such proxy components and is implementing platform-wide developer policies explicitly prohibiting residential proxy SDKs, while working to identify and remove existing apps in its store.
The reporting also notes that LG previously announced plans to suspend similar apps following findings in its own TV app store, where a significant share of apps allegedly allowed third parties to route internet traffic through users’ TVs.