Samsung Bans Smart TV Apps Sharing User Internet Access
Samsung is banning smart TV apps that funnel user internet connections to third parties, a move prompted by research revealing the practice in popular apps, including a game endorsed by the company.

Samsung has announced it will ban smart TV applications that allow third parties to route their internet traffic through users' home connections. The decision follows security research highlighting the widespread use of this practice, known as residential proxy networks (resproxies), in apps available on the company's platform. Some of these apps, including an officially endorsed Pac-Man game, were found to contain code that effectively turns a user's television into an unwitting gateway for external internet activity.
The research, conducted by Norwegian cybersecurity firm Mnemonic, uncovered that a significant number of apps on Samsung's Smart TV platform incorporated software that enables outsiders to tunnel their web traffic through ordinary home and office internet connections. These apps, often described as basic shells, can funnel traffic even when they are not actively running, posing a substantial security risk. Mnemonic's findings revealed that the code review process might not always reflect the full functionality of an app, a loophole exploited by some developers.
"What was reviewed is not necessarily what is running," stated Harrison Sand, an offensive security consultant at Mnemonic, in his analysis. The practice of using residential proxy networks is increasingly linked to cybercrime activities. While not inherently illegal and sometimes used for legitimate purposes like bypassing censorship or data scraping for AI model training, these networks have gained a reputation for enabling hackers to conduct malicious activities while obscuring their true origin.
The Growing Threat of Residential Proxies
Residential proxy networks operate by allowing individuals or entities to pay for the use of internet connections belonging to everyday users. This network traffic is challenging to distinguish from legitimate user activity, as it appears to originate from a standard home or office IP address. Furthermore, the data passing through these connections is typically encrypted, making it difficult for security firms to inspect or intercept, creating a significant hurdle for cybersecurity professionals.
Mnemonic's Sand gained deep access to the internal workings of a Samsung smart TV, analyzing network traffic to identify apps sharing the device's internet connection. He discovered that the popular Pac-Man game, which Samsung had previously featured in its "Editor's Choice" section, contained resproxy code from Bright Data, an Israeli company specializing in proxy networks. This code remained dormant until the user accepted a consent screen, after which it would run in the background, turning the TV into an exit node for external traffic.
Sand's analysis suggested that a significant portion of the traffic routed through Bright Data's network via the smart TV was used for large-scale scraping of LinkedIn profiles and for collecting data for AI training data. He noted that this represented only a fraction of the total traffic processed by the network. The potential for misuse is significant; Sand warned that a simple server-side code change could instantly transform millions of Samsung smart TVs into a vast botnet for malicious purposes.
In response to the findings, a Samsung spokesperson confirmed the company's commitment to user security. "We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform," the spokesperson said. "We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components." This action by Samsung follows a similar move by LG, which announced last month that it would ban apps employing resproxy software after research indicated that approximately 42% of apps on its store utilized such technology.
