LG Electronics USA says it will suspend smart TV apps that keep using residential proxy software, a move aimed at stopping apps from turning televisions into rentable internet relay points for third parties.
The decision follows research from security firm Spur, which found residential proxy software development kits in more than 42 percent of apps available for LG’s webOS smart TV platform. Spur also reported that more than a quarter of apps built for Samsung’s Tizen OS contained similar components.
The mechanism is plain enough, and ugly enough. A developer embeds a proxy SDK in an app, usually as a monetization option. Once active, the TV can become a residential proxy node, meaning paying customers of the proxy provider can route traffic through the user’s home internet connection. To outside services, that traffic can look like it came from the household, not from the proxy customer.
John Taylor, LG senior vice president, told KrebsOnSecurity that LG is working with developers to remove the proxy feature from apps on webOS. Taylor said apps that do not remove it will be suspended.
Taylor said in an emailed statement that using LG smart TVs as part of a residential proxy network is not an intended use of the devices. He also said LG’s review of affected apps is already underway and that the company will strengthen how it evaluates developer-submitted apps, including apps that include residential proxy SDKs.
Proxy code turned up in ordinary TV apps
Spur said the proxy SDKs were not limited to obscure tools. The firm found them in smart TV apps including simple games, screensavers, and file utilities. In one example documented by Spur, a Pac-Man smart TV app from Bright Data gave users a choice between seeing ads in the game or allowing the TV to operate as a residential proxy node.
According to Spur, Bright Data accounted for most of the proxy SDKs detected across both LG and Samsung smart TV apps. KrebsOnSecurity reported that Bright Data did not respond to requests for comment.
Proxy providers named in Spur’s report say they run know-your-customer checks and allow legitimate uses, often tied to content scraping. They also say they use technical controls meant to stop proxy customers from interacting with other devices on a user’s local network.
Spur’s argument is narrower and more damning for TV platforms: the problem is placing this kind of network infrastructure inside devices that many buyers treat as appliances, not computers they are expected to audit. Trevor Sutter of Spur wrote that a one-time consent prompt inside a TV app does not provide meaningful transparency, continuing control, or platform oversight. He also said the risk grows when the person granting consent could be someone in the household who should not make that decision, including a minor.
LG is also catching heat over monitor software
The proxy cleanup lands while LG is facing a separate complaint about software bundled with some of its high-end LCD monitors.
The YouTube channel Gamers Nexus reported this week that certain LG LCD monitors automatically install an app promoting paid McAfee antivirus subscriptions. According to Gamers Nexus, the app arrives through Windows Update and installs without an approval prompt.
That is a different issue from proxy SDKs in smart TV apps, but it points to the same basic problem: hardware vendors keep finding ways to make screens behave like software distribution channels. Users bought a TV or a monitor. They did not buy a tiny ad-supported server with a side hustle.
This story draws on original reporting from Krebs on Security.