Samsung is tightening its smart TV app rules after security researchers discovered that some applications could use a television’s internet connection to route traffic for outside customers.
The affected apps contain residential proxy software development kits, or SDKs. Once activated, this software can turn a smart TV into an exit point for someone else’s web requests, making that activity appear to originate from the TV owner’s home or office network.
Samsung told TechCrunch that it had restricted new app registrations containing the functionality. The company is also introducing platform-wide policies banning residential proxy SDKs and identifying existing apps that need to be removed.
The announcement is reassuring, but it also exposes a larger problem: smart televisions are computers that remain online for years, yet their apps rarely receive the same scrutiny as software installed on phones or laptops.
What Is a Residential Proxy?
A residential proxy routes internet traffic through an ordinary household connection rather than a commercial data centre.
To the website receiving the request, the traffic appears to come from the household’s public IP address. Companies use these networks for legitimate purposes such as checking regional prices, testing websites, collecting publicly available information and accessing geographically localised results.
Residential proxies are also attractive to malicious users because they can conceal the real origin of suspicious activity. A request coming from a normal home connection may be less likely to trigger automated security systems than one originating from a known hosting provider or previously identified malicious server.
Proxy providers build these networks by recruiting internet-connected devices. App developers can add a provider’s SDK to their software and receive revenue when participating devices supply bandwidth and IP addresses to the network.
The issue is not that every residential proxy service is automatically criminal. The concern is that consumers may not understand that a simple game, clock or screensaver can continue making their internet connection available to third parties after the visible app has closed.
A Pac-Man Game Helped Reveal the Problem
Norwegian cybersecurity company Mnemonic investigated the issue by gaining deep access to the operating system of a Samsung television and examining installed applications and network activity.
One of the apps it studied was a licensed Pac-Man game developed by Play.Works. Samsung had promoted the game in the Editor’s Choice area of its television app store, giving it a level of visibility and implied trust that an unknown third-party app might not otherwise receive.
The researchers found that the game contained a residential proxy SDK from Bright Data. Installing Pac-Man did not automatically turn the television into a proxy during the testing. The SDK was dormant and depended on configuration data loaded from a remote server.
That distinction is important. The researchers did not establish that every television containing the game was secretly routing traffic. They demonstrated that the functionality was already embedded and could be enabled remotely. When enabled, the app was designed to present a consent screen before activating the service.
Mnemonic found the proxy functionality enabled in another Play.Works game. After consent was provided, a background service continued operating when the user moved away from the app. It remained active until the app was deleted or participation was otherwise stopped.
The Consent Screen May Not Tell the Whole Story
Some apps offer users a choice between watching advertisements and allowing their internet connection to support web indexing or similar activities.
Technically, this can qualify as consent. The user is shown a notice and selects whether to participate. Proxy providers argue that their networks differ from malicious botnets because devices join voluntarily and customers are subjected to verification and usage controls.
Bright Data told researchers that its users opt in, can opt out and receive value in return. It also said customers are vetted and that technical controls are intended to prevent improper use.
The difficult question is whether the average television owner understands what the agreement means.
A person trying to begin a game may interpret the choice as little more than “watch advertisements or continue without them.” The wider consequences of lending a public IP address and internet connection to an external proxy network may not be obvious.
Consent can become even more complicated in shared households. A child, guest or other family member may accept the prompt even though they do not control the internet account and cannot meaningfully authorise the use of the household’s connection.
Why Smart TVs Make Attractive Proxy Devices
Smart TVs are particularly useful to proxy operators because they remain connected for long periods and are rarely inspected.
A phone user may notice battery drain, overheating, excessive mobile-data consumption or a suspicious background process. A television is normally plugged into power, connected to unlimited home broadband and treated more like furniture than a general-purpose computer.
Security company Spur scanned 6,038 Samsung and LG television applications and found residential proxy SDK indicators in 2,058 of them. Its research included games, screensavers, utilities and other lightweight apps that would not normally appear sensitive.
The researchers argued that developers have a financial incentive to use proxy SDKs because they can monetise applications without filling the screen with advertisements. The app remains free and visually unobtrusive while its background service generates revenue through the household’s internet connection.
Spur reported that more than a quarter of the Samsung Tizen apps it examined contained confirmed proxy SDK fingerprints. That finding does not prove that every identified app was actively routing traffic at the time of the scan, but it indicates that the underlying components were present at significant scale.
The Risk Is Larger Than Slower Internet
A residential proxy does not necessarily give an outsider direct access to personal photographs, passwords or television accounts. Its primary purpose is to route traffic through the household’s public IP address.
Even so, the arrangement creates several risks.
Websites may associate scraping, automated account activity or other suspicious requests with the household’s IP address. That could lead to additional verification checks, blocked access or reputational problems for the connection. Investigators initially examining harmful traffic may also see the proxy user’s address rather than the real customer behind the request.
The more serious concern involves the wider home network. A television normally shares a local network with routers, cameras, printers, storage devices and computers. Responsible proxy providers say they block access to private network addresses and restrict customers to approved destinations.
However, researchers warn that those protections depend on the SDK, the provider’s servers and continued enforcement of its policies. If a filter contains a vulnerability, is misconfigured or is deliberately changed, the proxy-enabled television could potentially become a route toward devices that were never intended to be accessible from the public internet.
The safest platform policy is therefore to prevent ordinary entertainment apps from providing third-party proxy services at all rather than expecting consumers to evaluate the technical safeguards themselves.
Samsung’s App-Review Problem Goes Beyond One SDK
Mnemonic’s investigation also revealed why conventional app-store reviews may struggle to detect changing behaviour.
Some Samsung TV applications contain very little functionality within the package submitted for review. Instead, they act as shells that load much of their code and content from a developer-controlled server.
This architecture has legitimate benefits. Developers can repair bugs, update games and change content without requiring a complete app-store submission each time.
It also creates a security gap. The code Samsung reviews may not be identical to what the television downloads and executes later. A developer could submit a compliant app, pass the review process and subsequently change its remotely delivered configuration or functionality.
Banning known residential proxy SDKs is an important first step, but effective enforcement may require Samsung to monitor network behaviour, restrict persistent background services and review remotely loaded code after an app has already been approved.
LG, Amazon and Roku Have Faced the Same Issue
Samsung is not the only television platform confronting residential proxy software.
LG announced in July that apps containing the functionality would be suspended unless their developers removed it. That decision followed research suggesting that approximately 42% of the examined apps in LG’s webOS store included residential proxy SDKs.
Amazon’s developer policy explicitly prohibits applications that facilitate third-party proxy services. Spur also reported that Roku had removed or blocked apps using similar SDKs after the issue was raised.
The differing responses show that proxy functionality is not an unavoidable feature of smart televisions. Platform owners can prohibit it, but only when their policies, technical controls and enforcement processes are capable of identifying the software.
What Samsung TV Owners Should Do
Owners do not need to disconnect every Samsung television immediately, and the research does not show that all Samsung smart TVs are affected.
The most practical response is to review installed applications and remove unfamiliar games, screensavers or utilities that are no longer used. Apps that offered fewer advertisements in exchange for allowing internet resources, IP addresses, web indexing or background network participation deserve particular attention.
The television’s operating system should also be kept updated so that future Samsung security and app-policy changes can be applied. Households with advanced network equipment may place smart televisions and other internet-connected appliances on a separate guest or Internet of Things network, reducing their ability to communicate directly with sensitive computers and storage devices.
Unexplained data use, repeated service blocks or unusual router activity may justify a closer network review. However, ordinary owners may find it difficult to identify encrypted proxy traffic without specialist monitoring tools, which is precisely why platform-level removal is more effective than placing the responsibility entirely on consumers.
Samsung’s Ban Is Necessary, but It Arrived Late
Samsung’s decision should reduce the number of television apps capable of converting household internet connections into proxy infrastructure.
The episode nevertheless raises uncomfortable questions about how so many apps containing the relevant SDKs reached smart televisions in the first place. One was not merely available in the store but promoted through Samsung’s own Editor’s Choice section.
A television app should perform the function its user reasonably expects. A Pac-Man game should run Pac-Man. A screensaver should display images. Neither should quietly become infrastructure for an external data-collection business after a household member accepts a briefly displayed prompt.
Samsung’s new prohibition recognises that this is not an appropriate form of smart TV monetisation. Its success will depend on whether the company can enforce the policy against apps whose behaviour can change long after their initial approval.