LG Moves to Purge Smart TV Apps of Hidden Residential Proxy SDKs Following Security Revelations

By: Global Technology & Cybersecurity Desk
Updated: July 22

Home appliance giant LG Electronics USA has announced an aggressive enforcement sweep targeting applications on its smart television platform that quietly convert consumers’ living rooms into traffic-routing relays for commercial proxy networks. The sweeping policy shift arrives less than a month after independent cybersecurity researchers revealed a staggering security oversight: nearly half of all available applications on LG’s webOS app store were secretly embedding software development kits (SDKs) that transformed everyday televisions into "always-on" residential proxy nodes.

While proxy networks have legitimate enterprise use cases—ranging from market research to content verification—their integration into consumer living room hardware has sparked intense debate. Security analysts warn that embedding these monetization mechanisms inside closed-ecosystem internet-connected televisions strips users of meaningful oversight, introduces severe local network visibility risks, and frequently bypasses the foundational security assumptions most consumers hold regarding household appliances.


Main Facts

The core of the controversy centers on how software developers monetize otherwise free or low-cost applications on smart televisions. By integrating residential proxy SDKs into utilities, games, and screensavers, developers can generate passive revenue by renting out a consumer’s broadband connection to third parties.

  • The Scale of the Problem: Independent security evaluations conducted by the firm Spur uncovered that over 42 percent of downloadable applications in LG’s webOS store included code designed to route unknown third-party internet traffic indefinitely through the user’s television. A similar, though smaller-scale, issue was discovered on Samsung’s Tizen OS, where more than a quarter of evaluated apps featured comparable components.
  • LG’s Policy Enforcement: In direct response to these findings, LG Senior Vice President John Taylor confirmed that the company is actively auditing its platform and forcing developers to strip out residential proxy functions. Apps that fail to comply face immediate suspension from the webOS marketplace.
  • The Industry Ecosystem: Prominent proxy network operators—most notably Bright Data, which accounted for the lion’s share of proxy SDK implementations across both LG and Samsung inventories—defend their practices, asserting that peer participation is strictly opt-in and backed by rigorous compliance and auditing standards.
  • Broader Corporate Friction: The crackdown on webOS apps runs parallel to independent controversies facing LG. Simultaneously, the company has faced criticism from hardware reviewers regarding software drivers for high-end monitors that silently push third-party antivirus subscriptions via Windows Update.

Chronology of Events

The unfolding narrative of the smart TV proxy crisis reveals a rapid escalation from academic disclosure to corporate enforcement:

  • Early July 2026: Security firm Spur publishes comprehensive research highlighting the quiet epidemic of residential proxy SDK integration within living room entertainment hubs, noting that over 42% of LG apps and 25% of Samsung apps feature proxy capabilities.
  • July 2, 2026: Investigative security reporting brings Spur’s findings to broader public prominence, connecting the smart TV proxy trend to larger infrastructural concerns, such as the simultaneous takedown and disruption of botnet-adjacent proxy platforms like NetNut.
  • Mid-July 2026: Hardware watchdog channels, including Gamers Nexus, expose separate software bundling practices by LG involving unprompted third-party antivirus installations on PC monitors, further intensifying scrutiny on LG’s software distribution policies.
  • Late July 2026: LG Senior Vice President John Taylor issues an official statement to security journalists, declaring that residential proxy networks are an "unintended use" for smart displays, signaling that enforcement actions, code reviews, and app suspensions are actively underway.
  • July 22, 2026: Proxy provider Bright Data issues a formal response defending its transparent opt-in architecture, independent audits, and rigorous Know-Your-Customer (KYC) frameworks.

Supporting Data & Ecosystem Analysis

To fully understand how a smart television app can morph into a commercial proxy node, one must examine the intersection of app monetization and the commercial proxy market.

Smart TV platforms like LG’s webOS and Samsung’s Tizen OS host thousands of lightweight applications, ranging from media players and weather widgets to casual arcade games like Pac-In-Time or variants of Pac-Man. Developing, updating, and maintaining these applications requires financial incentives. When direct subscriptions or continuous ad-serving options fall short, developers frequently turn to alternative revenue channels.

[Consumer Smart TV] 
       │ (Runs App with Hidden SDK)
       ▼
[Residential Proxy Node] <── (Rented out by Proxy Provider like Bright Data)
       │
       ▼
[Third-Party Traffic / Web Scraping] ──> [Target Websites / Servers]

Residential proxy networks work by pooling thousands of real consumer IP addresses—often assigned by traditional Internet Service Providers (ISPs)—and renting them to corporate clients. Because these IP addresses appear as genuine residential households rather than commercial data centers, they are heavily sought after for tasks such as:

  • Global ad verification
  • Price comparison scraping
  • Regional content testing
  • Cybersecurity threat intelligence gathering

According to Spur’s telemetry, however, the barrier between a benign application and an always-on relay node is dangerously thin. In many cases, applications bundled proxy SDKs into simple screensavers, basic file utility tools, and casual games. Some applications—such as certain variants of Pac-Man distributed through channels tied to proxy networks—offered users a binary choice: either sit through traditional ad units or agree to let the device operate as a proxy node.

However, security experts emphasize that a simple, one-time dialogue box hidden away in a TV setup menu or buried inside an application’s first-run agreement fails to meet the standard of informed, meaningful consent.


Official Responses

The stakeholders at the center of this controversy have offered sharply contrasting perspectives on responsibility, platform oversight, and user consent.

LG to Ban Residential Proxies from Smart TV Apps – Krebs on Security

LG Electronics

Addressing the findings directly, LG Senior Vice President John Taylor drew a firm line regarding what constitutes acceptable platform usage:

"A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform. If this option is not removed, these apps will be suspended."

Taylor added that LG’s internal review of developer submissions is already "well underway," noting that the company is actively tightening its vetting guidelines to permanently block proxy SDKs from entering the webOS ecosystem in the future.

Bright Data

As the primary proxy network identified in Spur’s research, Bright Data pushed back against the implication that its services operate deceptively. In a statement provided to media outlets, the company highlighted its rigorous compliance protocols:

"Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC. We remain committed to an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain."

Bright Data and its peers maintain that they enforce stringent Know-Your-Customer (KYC) checks to prevent malicious threat actors from abusing their infrastructure, alongside technical guardrails designed to prevent proxy users from probing or interacting with other connected devices residing on the local home network.

Security Researchers (Spur)

Despite industry assurances, independent researchers remain deeply skeptical of leaving proxy integration decisions in the hands of third-party app developers. Trevor Sutter of Spur highlighted the inherent danger of treating a shared household appliance like a personal computer:

"A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight. The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors."


Implications for Consumer Security and the Smart Home

The LG residential proxy incident highlights a broader, systemic vulnerability in the modern Internet of Things (IoT) landscape: the blurring lines between consumer convenience and commercial data infrastructure.

  1. The "Appification" of Appliances: Modern smart televisions are no longer simple display panels; they run full-fledged operating systems capable of executing complex code, managing local storage, and establishing persistent outbound connections. Consumers, however, rarely view their televisions with the same security posture they apply to desktop computers or smartphones.
  2. Local Network Blind Spots: While proxy providers implement technical countermeasures to segregate proxy traffic from a user’s internal local area network (LAN), the presence of unauthorized background SDKs running with elevated system permissions introduces an unnecessary attack surface. If a vulnerability is discovered within an SDK framework, threat actors could potentially pivot from the compromised smart TV into sensitive local devices, such as network-attached storage (NAS) units, home automation hubs, and personal computers.
  3. The Consent Dilemma in Shared Environments: Unlike personal mobile devices, smart televisions are inherently communal. A living room television is accessed by parents, children, guests, and visitors alike. A consent prompt accepted by a minor or an uninformed family member essentially signs away the household’s network reputation, turning an innocent home broadband connection into an unvetted relay for global web traffic.
  4. Platform Responsibility: LG’s proactive stance marks a positive turning point, proving that hardware manufacturers can—and should—enforce strict app store governance. However, the sheer volume of non-compliant apps uncovered by Spur (over 42%) demonstrates that historical app store vetting processes across the smart TV industry have been historically lax, reactive rather than preventative, and ill-equipped to police backdoor monetization techniques.

As LG pushes forward with its webOS app suspensions and audits, industry watchers will be closely monitoring whether competing manufacturers—including Samsung, Roku, and Google TV—follow suit with similar platform sweeps to reclaim consumer trust in the smart home ecosystem.