LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV. Proxy SDK prevalence among smart TV apps for LG (webOS) and Samsung (Tizen OS) televisions. Image: Spur.us. On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one’s television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components. Responding to questions about Spur’s research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended. “A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said. “If this option is not removed, these apps will be suspended.” Taylor said LG is committed to keeping residential proxy networks out of its smart TV apps going forward, and that the company’s review of those apps is “well underway now.” “As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs,” Taylor wrote in an emailed statement. App makers looking for ways to monetize their creations can turn to residential proxy providers, which pay developers to include SDKs that turn the user’s device into a residential proxy node that is rented to paying customers. In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and file utilities. A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node. Image: Spur.us. Spur’s report found the residential proxy network Bright Data accounted for a majority of proxy SDKs across both Samsung and LG smart TVs. In a statement shared with KrebsOnSecurity, Bright Data said its network is built on consent and responsibility and operates by LG and Samsung terms. “Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC,” the statement reads. “We remain committed to an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain.” Bright Data and other proxy providers named in Spur’s report all say they follow rigorous know-your-customer processes to validate legitimate uses of their services, which is often heavily tied to content-scraping activities by said customers. The proxy companies also say they incorporate technological countermeasures to prevent proxy service customers from being able to interact with and control other devices on the proxy user’s local network . Spur argues the problem is not that residential proxy networks exist, but rather that they are being embedded at scale in devices that most consumers do not think of as computers and are not equipped to audit. “A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight,” Spur’…
AI Analysis
Technical Summary
Research by Spur found that a significant portion of apps on LG's webOS smart TVs include residential proxy SDKs that turn the TVs into always-on proxy nodes, allowing third parties to route internet traffic through them. LG Electronics USA responded by committing to remove these proxy options from apps and suspending those that do not comply. The residential proxy networks, including Bright Data, operate by obtaining user consent at app installation but raise concerns about meaningful transparency and ongoing user control. LG is strengthening its app evaluation process to prevent such SDKs from being included in the future. This situation highlights risks related to smart TV apps embedding proxy functionality without clear user understanding, but it is not a software vulnerability or exploit in itself.
Potential Impact
The impact primarily concerns user privacy and potential misuse of smart TVs as proxy nodes without ongoing user awareness. This could lead to users' internet traffic being routed through their devices for third-party use, potentially exposing users to privacy risks or network misuse. However, there is no indication of direct exploitation or compromise of the TV devices themselves. The issue affects the integrity of the app ecosystem and user trust in smart TV platforms.
Mitigation Recommendations
LG is actively working with app developers to remove residential proxy SDKs from their smart TV apps and will suspend apps that fail to comply. Users should monitor app updates and LG's announcements. Since this is a platform policy enforcement rather than a software vulnerability, no patch is applicable. LG is enhancing its app review process to prevent future inclusion of such SDKs. Users concerned about privacy should review app permissions and avoid installing apps that offer proxy functionality.
LG to Ban Residential Proxies from Smart TV Apps
Description
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV. Proxy SDK prevalence among smart TV apps for LG (webOS) and Samsung (Tizen OS) televisions. Image: Spur.us. On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one’s television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components. Responding to questions about Spur’s research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended. “A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said. “If this option is not removed, these apps will be suspended.” Taylor said LG is committed to keeping residential proxy networks out of its smart TV apps going forward, and that the company’s review of those apps is “well underway now.” “As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs,” Taylor wrote in an emailed statement. App makers looking for ways to monetize their creations can turn to residential proxy providers, which pay developers to include SDKs that turn the user’s device into a residential proxy node that is rented to paying customers. In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and file utilities. A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node. Image: Spur.us. Spur’s report found the residential proxy network Bright Data accounted for a majority of proxy SDKs across both Samsung and LG smart TVs. In a statement shared with KrebsOnSecurity, Bright Data said its network is built on consent and responsibility and operates by LG and Samsung terms. “Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC,” the statement reads. “We remain committed to an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain.” Bright Data and other proxy providers named in Spur’s report all say they follow rigorous know-your-customer processes to validate legitimate uses of their services, which is often heavily tied to content-scraping activities by said customers. The proxy companies also say they incorporate technological countermeasures to prevent proxy service customers from being able to interact with and control other devices on the proxy user’s local network . Spur argues the problem is not that residential proxy networks exist, but rather that they are being embedded at scale in devices that most consumers do not think of as computers and are not equipped to audit. “A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight,” Spur’…
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Research by Spur found that a significant portion of apps on LG's webOS smart TVs include residential proxy SDKs that turn the TVs into always-on proxy nodes, allowing third parties to route internet traffic through them. LG Electronics USA responded by committing to remove these proxy options from apps and suspending those that do not comply. The residential proxy networks, including Bright Data, operate by obtaining user consent at app installation but raise concerns about meaningful transparency and ongoing user control. LG is strengthening its app evaluation process to prevent such SDKs from being included in the future. This situation highlights risks related to smart TV apps embedding proxy functionality without clear user understanding, but it is not a software vulnerability or exploit in itself.
Potential Impact
The impact primarily concerns user privacy and potential misuse of smart TVs as proxy nodes without ongoing user awareness. This could lead to users' internet traffic being routed through their devices for third-party use, potentially exposing users to privacy risks or network misuse. However, there is no indication of direct exploitation or compromise of the TV devices themselves. The issue affects the integrity of the app ecosystem and user trust in smart TV platforms.
Defensive Guidance
LG is actively working with app developers to remove residential proxy SDKs from their smart TV apps and will suspend apps that fail to comply. Users should monitor app updates and LG's announcements. Since this is a platform policy enforcement rather than a software vulnerability, no patch is applicable. LG is enhancing its app review process to prevent future inclusion of such SDKs. Users concerned about privacy should review app permissions and avoid installing apps that offer proxy functionality.
Technical Details
- Article Source
- {"url":"https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/","fetched":true,"fetchedAt":"2026-07-22T01:26:07.440Z","wordCount":814}
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6a601c2f9c2644c7f81bd28b
Added to database: 07/22/2026, 01:26:07 UTC
Last enriched: 08/15/2026, 05:06:37 UTC
Last updated: 09/03/2026, 11:27:09 UTC
Views: 172
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.