
Your Samsung smart TV may have been routing strangers’ internet traffic
Samsung has banned smart TV apps that secretly turn your television into a proxy exit node — letting unknown third parties route their internet traffic through your home connection. The move comes after Norwegian cybersecurity firm Mnemonic found that more than a quarter of all apps in Samsung’s Tizen app store carried residential proxy software development kits (SDKs).
LG took similar action last month after discovering that over 42 percent of apps on its webOS platform contained the same kind of code.
What these proxy apps actually do
The apps in question look normal on the surface — one of the flagged apps was a Pac-Man game Samsung had featured in its own “Editor’s Choice” section. But underneath, they contain code from companies like Israel-based Bright Data that can convert your TV into an always-on residential proxy exit node.
In practice, this means someone else’s web requests get routed through your home IP address. To any website or service on the receiving end, that traffic looks like it’s coming from your house. Mnemonic researcher Harrison Sand rooted a Samsung TV and captured the traffic, observing large-scale LinkedIn profile harvesting and AI training data collection being funnelled through these nodes.
The apps bypass Samsung’s code review because they work as thin shells — they pass static analysis cleanly, then load their real functionality from remote servers after installation. As Sand put it: “What was reviewed is not necessarily what is running.”
What Samsung is doing about it
Samsung said it has already blocked new app submissions with proxy functionality and is removing existing ones. In a statement to TechCrunch, the company said:
“We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform. We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components.”
Samsung has not given a timeline for when the cleanup will be complete.
What this means if you own a Samsung or LG smart TV
If you have a Samsung or LG smart TV, any app you have installed could potentially be one of the affected ones — the sheer percentages (over 25 percent on Samsung, over 42 percent on LG) make it likely. Here is what you can do:
- Remove apps you don’t actively use. The fewer apps installed, the smaller the attack surface. That free game or utility you downloaded once and forgot about is exactly the kind of app that carried these SDKs.
- Check for app updates. Samsung says it is actively removing the proxy code, so updated versions of legitimate apps may be cleaned up over time.
- Monitor your network. If your internet has felt unusually slow or your ISP has flagged unusual traffic patterns, a proxy-compromised smart TV could be the reason.
The bigger problem with smart TV app stores
This is not just a Samsung or LG problem — it is a structural weakness of smart TV platforms. TV app stores have far less scrutiny than mobile app stores, and developers can push server-side changes after passing initial review. The fact that a quarter to nearly half of all apps on two of the world’s largest TV platforms carried proxy code — and nobody caught it until an external security firm investigated — says something uncomfortable about how seriously TV manufacturers have treated software security on devices that sit permanently connected to home networks.
Samsung and LG deserve credit for acting once the problem was exposed. But the question is why it took an outside researcher to find something that affected hundreds of millions of installed apps.
Sources: TechCrunch, PPC Land
