Skip to main content
CybersecurityHacking

LG Moves to Block Residential Proxies in Smart TV Apps

LG smart TV on in a living room with scattered app icons and remotes nearby.

“A residential proxy network is not an intended use for LG smart TVs,” the company’s senior vice president John Taylor told KrebsOnSecurity — and LG is now moving to make that statement enforceable.

Spur’s measurement: more than 42 percent of webOS apps contain proxy SDKs

The security firm Spur surveyed smart TV app stores and found that “more than 42 percent” of games and other apps available for download on LG’s webOS store include software development kits (SDKs) that can turn a television into an always-on residential proxy node. Spur also reported that “more than a quarter” of apps made for Samsung’s Tizen operating system contained similar residential-proxy components. The SDKs were observed bundled with a wide range of app types, including simple games, screensavers and file utilities.

Spur warned that embedding proxy SDKs at scale in devices “that most consumers do not think of as computers and are not equipped to audit” amplifies risk, noting that “a one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight.” Spur’s Trevor Sutter specifically called out the danger when consent comes from household members who should not give it, “such as minors.”

LG’s response: remove the option or face suspension

Responding to Spur’s research, LG Electronics USA said it is working with app developers to remove the residential proxy option from apps on its webOS platform and that developers who fail to comply will have their apps suspended. “If this option is not removed, these apps will be suspended,” John Taylor told KrebsOnSecurity.

In an emailed statement, Taylor added that LG’s review of those apps is “well underway now” and that the company will “continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs.”

How monetization and proxy suppliers fit together

Spur described a monetization pipeline in which app makers turn to residential proxy providers that pay developers to include SDKs converting users’ devices into rented proxy nodes. The report named several proxy providers and said Bright Data accounted for a majority of proxy SDKs observed across both LG and Samsung smart TVs. Bright Data did not respond to requests for comment.

The proxy companies named in Spur’s report told the researchers they perform rigorous know-your-customer (KYC) checks tied to content-scraping activities and that they employ technological countermeasures intended to prevent proxy customers from interacting with or controlling other devices on the proxy user’s local network.

Concrete examples: a Pac-Man app and a separate monitor controversy

Spur highlighted specific app behavior: a Pac-Man smart TV app from Bright Data reportedly offers users a choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node. That juxtaposition—an otherwise benign game offering an opt-in to turn a TV into a proxy endpoint—was central to Spur’s concern about transparency and consent.

Separately, LG has faced scrutiny for another software-distribution practice. The YouTube channel Gamers Nexus showed that certain LG LCD monitors will automatically install an app promoting paid McAfee antivirus subscriptions, and that the app arrives through Windows Update without an approval prompt.

What this means for developers, users, and security teams

  • Developers: LG has put developers on notice — remove residential-proxy options from webOS apps or risk suspension — and the company says it will strengthen its app-evaluation process.
  • End users and the public: Consumers can encounter proxy SDKs inside a range of TV apps, and Spur cautioned that buried consent prompts are not a substitute for ongoing transparency or control, especially when household members who should not give consent may be the ones clicking prompts.
  • Security and procurement teams: Spur’s finding that Bright Data accounted for a majority of proxy SDKs, and that similar components were present on Samsung Tizen apps, highlights a cross-platform distribution pattern that security teams and device purchasers should inventory and address when assessing device behavior.

LG’s commitment to remove residential proxy capabilities from webOS apps and to enforce suspensions marks a decisive step by a platform operator; Spur’s parallel finding that more than a quarter of Samsung’s Tizen apps included similar SDKs leaves the broader market question unresolved. For now, LG says its review is already underway — and the onus is on app developers and proxy providers to make their practices visible and compatible with platform rules.

Original story