42% of LG smart TV apps sell your internet connection to strangers: LG says no more
Your smart TV is working for someone else.

Images by Shutterstock.
- LG Electronics says it is working with developers to remove proxy options from their webOS apps or risk suspension.
- Forty-two percent of LG smart TV apps and 26.5% of Samsung apps were found to contain residential proxy SDKs.
- Proxy SDKs allow strangers to use your home internet connection, potentially posing security and privacy risks.
LG sells its smart TVs by the millions, and if you download a fish tank screensaver, a sketchy movie app, or a game, 42% of the apps include built-in proxy functionality that lets strangers piggyback on your internet connection as if it were their own. After being called out, LG now says it will suspend any apps acting as residential proxy nodes, according to a report by Brian Krebs.
Last month, security researchers at Spur, a threat intelligence firm specializing in detecting threats hidden behind VPNs and residential proxies, shared an unsettling discovery.
A huge proportion of apps across the LG and Samsung TV stores are “laced with proxies” – contain functionality of selling IP addresses to strangers, and users might not even be aware that someone is using their internet connection as their own.
Out of 6,038 scanned LG and Samsung apps, 2,058 contained proxy SDKs (software development kits).
“We found it everywhere,” the report reads.
“On screen, it’s a relaxing fish tank. Or a clock. Or solitaire. Or puppies. Under the hood, it is a residential proxy: software that can send other people's internet traffic out through your living room.”
Over 42% of LG TV (webOS) apps included the functionality, while Samsung (Tizen OS) apps contained it 26.5% of the time.
Residential proxy services are not necessarily all bad – they usually provide legitimate services for companies to collect data, verify ads, monitor SEO, market research, and others. Responsible providers say they require permission and safeguard user data.
However, malicious uses also exist. Just weeks earlier, Google and the FBI busted a massive residential proxy botnet dubbed NetNut that hijacked over 2 million everyday consumer devices, such as smart TVs and streaming boxes, for covert cybercrime and espionage. Cybercrime gangs can easily disguise their traffic using these services.
Similarly, at the beginning of the year, another residential proxy operation, IPIDEA, was taken down.
However, after being called out, it appears that LG’s stance towards proxy apps is changing.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Krebs on Security, a blog by seasoned cybersecurity professional Brian Krebs, reports that LG plans to suspend any app that turns a TV into a residential proxy node, because this is not the intended use for smart TVs.
“LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform. If this option is not removed, these apps will be suspended,” the blog quotes John Taylor, Senior Vice President at LG.
Cybernews couldn’t find any changes or mentions of residential proxies in LG’s developer documentation. The LG Privacy guideline directs developers to create apps with “Privacy by Design” and “Secure by Design” approaches.
“Ensure that the app requests only the least privilege necessary for its operation,” the guide states.
Check if your data has been leaked
Clicking on “Agree” is considered consent, and users don’t understand what they are signing up for
When users download an app or game with proxy SDKs (software development kits), they are presented with a general consent form that usually contains only two buttons: agree or dismiss.
“Prompts say the proxy can keep running after the app is closed,” Spur researchers explain in the report.
Some apps even force users to choose: play the “Pac-Man” game with ads or ad-free, but let it use the TV’s internet connection for web indexing.
The convoluted prompts usually explain that the IP address and free resources will be used “to download public web data from the internet.”
Most people do not have a working mental model for what it means to sell access to their residential IP addressSpur's research.
The researchers warn that a one-time agree click allows the app to keep monetizing the connection as long as it remains installed. Users have no idea who is using their internet or for what, but their IPs end up in the security logs.
“The risk is not limited to someone borrowing your public IP address … If the proxy provider decides to allow requests to private or local addresses, or if their filtering fails, that TV becomes a foothold for reaching things that were never meant to be exposed to the internet: router admin panels, NAS devices, printers, cameras, developer machines, and other apps listening on local ports,” the researchers warn.
A smart TV is the perfect host for a proxy, as it stays connected at all times and incurs no battery drain or cellular bill spikes. But the researchers believe that a TV app shouldn’t be able to turn a living-room device into someone else’s node. Amazon and Roku have banned this software, and researchers have urged LG and Samsung to follow suit.
Spur also detailed that only a few firms are responsible for the majority of proxy SDKs found in apps, and in some cases, the app acts like a wrapper: shovelware games, screensavers, and other low-value utilities.
The company flagged Bright SDK, from Bright Data, in the most, 367, proxy-flagged apps. The vendor said that consent separates a legitimate network from a nefarious one.
“Bright Data built this framework for consented networks that are intentionally discoverable and therefore accountable. Our practices are scrutinized by independent auditors and security companies,” the company said.