All posts

Your Smart TV Might Be Renting Out Your Internet Connection

iot-securityprivacyresidential-proxiessupply-chainconsumer-securityciso
July 23, 2026 · PlayCISO

Security research firm Spur found residential-proxy SDKs baked into 42% of apps in LG's webOS store and over 25% of apps in Samsung's Tizen store — quietly turning the TV into an exit node that strangers' internet traffic routes through, without the owner ever knowing. LG has now confirmed it will suspend non-compliant apps. Samsung has said nothing.

What a "Residential Proxy" Actually Is

A residential proxy is an IP address that belongs to a real home internet connection rather than a data center. That distinction matters commercially: traffic from a residential IP looks like an ordinary person browsing, which makes it far harder for websites to detect and block than traffic from an obviously-a-server data-center IP. Residential proxy networks exist specifically to sell that legitimacy.

The business model Spur uncovered is simple. A proxy provider — Bright Data was named as the largest player across both platforms — pays app developers to bundle an SDK into their smart TV apps. Once installed, that SDK turns the TV into a proxy node. The provider then rents access to that pool of real home IP addresses to paying customers, who use them for large-scale web scraping, ad verification, sneaker-bot shopping, and — increasingly — harvesting data to train AI models. The TV owner sees none of the money and gave no meaningful consent; the developer gets paid per device.

Why the TV, Specifically

Smart TVs are close to the ideal host for this. They are almost always on and connected. They run apps from a walled-garden store that most owners never audit. Owners overwhelmingly treat the TV as an appliance, not a computer — nobody runs endpoint monitoring on a television. And unlike a phone or laptop, there's no obvious battery drain, fan noise, or slowdown to tip someone off that background processes are eating their bandwidth. It's a computer that nobody treats as one, which is exactly the profile a covert proxy network wants.

LG's Response — and the Gap It Leaves

LG's SVP John Taylor told Krebs on Security that "a residential proxy network is not an intended use for LG smart TVs," and that LG is working with developers to strip the proxy capability from webOS apps, with non-compliant apps to be suspended. That's a real fix, for one platform.

It fixes nothing for Samsung's Tizen store, where the infection rate Spur measured was actually not far behind LG's — over a quarter of apps. As of this writing, Samsung hasn't issued a comparable statement or remediation timeline. The exact same monetization pattern, on the platform with the larger global TV market share, is unaddressed.

What This Means for Security Teams

  • Your network perimeter includes devices you don't manage. Smart TVs, streaming boxes, and similar consumer IoT devices connect to corporate guest networks, break rooms, conference rooms, and — increasingly — remote employees' home networks that host corporate VPN traffic. A proxy SDK on that TV means unknown third-party traffic shares the same NAT gateway as your employee's work session.
  • App-store review didn't catch this at scale. Both storefronts approved these apps. Vendor-store approval is a floor, not a security control — the same lesson mobile app stores have taught repeatedly.
  • This is a supply-chain problem wearing a consumer-electronics costume. The developers likely didn't build proxy infrastructure themselves — they integrated a monetization SDK, the same way countless mobile apps integrate ad SDKs, without necessarily auditing what that SDK does with the user's connection.
  • "It's just a TV" is no longer a valid risk-acceptance line. Any always-on, internet-connected device on a network you're responsible for is a potential proxy node, a potential pivot point, and a potential source of attributable-to-you traffic if someone uses that rented IP for something illegal.

The Broader Pattern

This is the residential-proxy economy showing up somewhere new, not something new. The same underlying market — pay device owners' bandwidth for legitimacy-laundered scraping traffic — has previously shown up in "free VPN" apps, browser extensions, and Android SDKs. Smart TVs are just the newest, least-monitored host. Expect the same pattern in the next category of always-on consumer hardware: routers, smart speakers, and connected appliances are all structurally identical targets.

Full story: krebsonsecurity.com — LG to Ban Residential Proxies from Smart TV Apps


Think your team would catch a supply-chain risk hiding in "harmless" consumer hardware on the network? Work a live SOC case →

Ready to practise the decisions these articles describe?

Run a free War Room →