Smart TVs secretly acting as proxies: LG clamps down on 42.5% of infected apps
Your LG or Samsung TV might be routing strangers' traffic without your knowledge.
Cybersecurity firm Spur examined 6,038 smart TV apps across LG's webOS and Samsung's Tizen platforms, revealing that 2,058 apps (about 34%) contained residential proxy SDKs. The code turns your TV into a proxy node, using your IP address to route other people's traffic without explicit, ongoing consent. LG's senior vice president John Taylor confirmed the company is actively working with developers to remove proxy functionality, threatening app suspension for non-compliance. Samsung has not yet commented.
Residential proxies are legitimate for tasks like bypassing geo-restrictions or web scraping, but embedding them in consumer devices without transparency creates serious security risks. A compromised proxy provider could expose your TV to botnet traffic or link your home IP to illegal activity. The problem is compounded by smart TVs' always-on nature and lack of robust security oversight compared to PCs or phones. Researchers emphasized that buried one-time consent prompts are not meaningful transparency. Users are advised to review app permissions and disable unused third-party apps.
- Spur found 42.5% of LG webOS apps and 26.5% of Samsung Tizen apps contain hidden residential proxy SDKs.
- LG is suspending any TV app that refuses to remove the proxy code; review is 'well underway'.
- Hidden proxies can route botnet traffic through your home IP, risking association with cyberattacks.
Why It Matters
Your living room device could be a cybercrime relay—without you ever noticing.