Samsung has begun restricting apps on its Smart TV platform that incorporate proxy functionalities to share users' internet connections with outside parties. This move follows security research conducted by the Norwegian cybersecurity firm Mnemonic, which identified code within popular Samsung Smart TV apps designed to share an owner's connection with strangers.

The research highlighted a Pac-Man game, featured in Samsung’s “Editor’s Choice” section, which was found to contain residential proxy code from Bright Data, an Israel-based company. Harrison Sand, an offensive security consultant at Mnemonic, observed that the proxy code in the game remains dormant until a user accepts a consent screen.

What was reviewed is not necessarily what is running
— Harrison Sand, offensive security consultant at Mnemonic

Sand warned that a code change on a web server could potentially activate hundreds of millions of smart TVs into a botnet. According to app developers, some applications on the Samsung Smart TV platform have been installed on hundreds of millions of devices.

Samsung and LG response

A Samsung spokesperson stated that the company has already restricted new app registrations that incorporate such proxy functionalities. The spokesperson added that Samsung is implementing strict platform-wide developer policies that explicitly ban residential proxy SDKs.


The restrictions follow a similar move by LG, which announced last month that it would ban apps containing residential proxy software. Recent reporting found that approximately 42% of apps on the LG app store had enlisted a smart TV into a proxy network.

Residential proxy code is not limited to televisions; it can also be found in consumer phone apps, digital frames, and Android streaming boxes.

42%

Of apps on the LG app store were found to enlist a smart TV into a proxy network