Samsung Restricts Smart TV Apps Sharing Users’ Internet Connections
Recent security analysis has uncovered that many popular Samsung smart TV applications include code that allows the sharing of users’ internet connections with outside entities, posing significant hijacking threats to millions of Samsung smart TVs. This was disclosed on Monday.
Developers have indicated that some of these apps have been installed on hundreds of millions of smart TVs in homes across the globe.
One such application was a basic Pac-Man game that Samsung actively promoted and featured in its “Editor’s Choice” section on users’ TV interfaces.
These apps encompass software that reroutes external web traffic through ordinary home and office internet connections, referred to as residential proxy networks (or “resproxies”), which have been increasingly linked to cybercrime activities. When initiated, apps containing resproxy code can turn a smart TV into a constantly active tunnel for third parties to route their web traffic through, known as an exit node—even if the app is not currently in use.
The security study performed by Norwegian cybersecurity firm Mnemonic highlights a series of problems that allow low-quality applications to thrive in Samsung’s app store, featuring code that jeopardizes user safety by granting unauthorized access to their internet connections.
Many of these applications are simple frameworks, containing just a few lines of code, and are mainly intended to pull content from other websites, such as games. Though these smart TV applications retrieve information from different servers, any evaluation of these apps only reveals the minimal code present, not the actual content.
“What has been reviewed may not accurately reflect operational realities,” remarked Harrison Sand, an offensive security consultant at Mnemonic.
In response to TechCrunch’s inquiry regarding the findings, Samsung communicated via email its commitment to prohibiting apps that share users’ internet connections and removing those with such capabilities.
“We have already restricted new app registrations that involve such proxy functionalities on our Smart TV platform,” a Samsung spokesperson stated. “We are in the process of implementing rigorous platform-wide developer policies that explicitly prohibit residential proxy SDKs and are actively working to identify and eliminate all apps currently available in our store that include these elements.”
This action follows LG’s announcement last month to ban apps containing resproxy software after reports suggested that around 42% of the apps in its app store were enlisting smart TVs into a proxy network.
Understanding a Residential Proxy Network
The research also offers a rare perspective on a residential proxy network.
Resproxy code can also exist in typical consumer mobile apps and other electronic devices, such as digital picture frames and Android streaming boxes, which can share that device’s internet connection.
Whenever a resproxy app or device connects to the internet, an outsider can pay to access it.
Resproxies are not automatically illegal. Some are utilized to evade censorship by routing internet traffic through seemingly ordinary residential homes. For example, AI companies increasingly rely on resproxies to collect data from various online sources simultaneously for training their AI models.
However, cybersecurity experts contend that resproxies have developed a reputation for facilitating hackers and spies in carrying out cyberattacks and data breaches while concealing their illicit activities.
Cybersecurity firms find it challenging to combat resproxies because the network traffic appears to stem from a regular household, rather than an overseas malicious hacker, as one might expect.
Moreover, the network traffic that passes through a user’s device over resproxies is typically encrypted, rendering it nearly impossible to decode and scrutinize.
By rooting the software of a Samsung smart TV, Mnemonic’s Sand obtained unfettered access to the television’s internal systems and analyzed all network traffic that flowed in and out of the TV, including any apps that were sharing the smart TV’s internet connection with third parties.
He discovered that the Pac-Man game included resproxy code from Bright Data, an Israeli company that provides proxy networks claiming access to millions of residential networks worldwide. The company also operates a marketplace for selling access to scraped data sets, which are produced from a network of enlisted smart TVs acting as exit nodes to collect large volumes of public data from the internet while circumventing systems designed to prevent scraping.
Sand noted that Bright Data’s resproxy code activated when the Pac-Man game was launched, but clarified that this did not instantly convert the Samsung smart TV into an exit node. According to Sand, the resproxy code remains dormant until the user consents through a consent screen, allowing it to run in the background until the app is uninstalled.
Besides the need for user consent to enroll their device into a resproxy, Sand warned that a “simple code change on a web server” could instantaneously activate hundreds of millions of smart TVs into a potentially harmful botnet.
Having access to the network data flowing through his smart TV, Sand observed that a significant portion indicated the use of the resproxy network for extensive scraping of LinkedIn profiles and the collection of data for AI training. He mentioned that he saw only a small fraction of what was routed through Bright Data’s network.
Bright Data did not respond to a request for comment.
When you make purchases through links in our articles, we may earn a small commission. This does not influence our editorial independence.


