Samsung Bans Smart TV Apps That Route Strangers’ Traffic Through Users’ Internet Connections

Samsung announced in August 2026 that it is banning apps on its smart TV platform that share users’ internet connections with third parties, after security research found that several popular apps contained code enrolling televisions into residential proxy networks.

The research, published Monday by Norwegian cybersecurity company Mnemonic, found that apps available on Samsung’s app store — some claiming hundreds of millions of installs — contained software that funnels outside web traffic through home and office internet connections. At least one affected app was a Pac-Man game that Samsung had featured in its “Editor’s Choice” section. When opened, these apps can turn a smart TV into an always-on traffic tunnel, or “exit node,” even after the app is closed.

Mnemonic’s Harrison Sand, an offensive security consultant, rooted a Samsung smart TV to analyze its network traffic and identified resproxy code from Bright Data, an Israel-based company that provides proxy networks and sells access to scraped datasets. Sand found the code activated only after a user accepted a consent screen, but warned that “a simple code change on a web server” could instantly activate hundreds of millions of TVs into a potentially malicious botnet. Network traffic he observed suggested the proxy network was being used to scrape LinkedIn profiles and collect AI training data.

Samsung responded by restricting new app registrations that include proxy functionality and said it is implementing platform-wide policies explicitly banning residential proxy SDKs, while working to remove existing apps containing such code. The move follows a similar announcement by LG last month, after reporting found that around 42% of apps on LG’s app store enlisted smart TVs into proxy networks.

Residential proxy networks are not inherently illegal — they are used for purposes including evading censorship and scraping web data — but cybersecurity companies say they are increasingly linked to cyberattacks and data breaches, partly because the traffic appears to originate from ordinary households rather than malicious actors.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top