LG Electronics USA to Suspend Smart TV Apps Featuring Residential Proxy Functionality

LG Electronics USA announced this week its intention to suspend any applications built for its smart TVs that transform a user’s television into an always-on residential proxy node. This decisive action comes less than a month after security researchers revealed a significant vulnerability: over 42 percent of apps available on LG’s webOS store allow unknown third parties to route their internet traffic through users’ televisions. The revelation has ignited a debate about user privacy, app monetization strategies, and the evolving landscape of smart device security.
The Discovery of Pervasive Proxy SDKs
The catalyst for LG’s announcement was a comprehensive report released on July 2 by the cybersecurity firm Spur. The research meticulously examined the prevalence of residential proxy software development kits (SDKs) within smart TV applications. Spur’s findings were stark: on LG’s webOS platform, more than 42 percent of downloadable applications contained SDKs that effectively turned the television into a permanent proxy node. This meant that the user’s internet connection could be rerouted through their device without their explicit, ongoing consent, potentially for activities they were unaware of.
The problem was not confined to LG. Spur’s investigation also found that over a quarter of applications designed for Samsung’s Tizen operating system exhibited similar residential proxy components. This widespread integration of proxy SDKs across major smart TV platforms highlighted a systemic issue in how applications are developed and vetted, raising concerns about the potential for misuse of user bandwidth and privacy.
LG’s Swift Response and Policy Shift
In response to Spur’s findings, John Taylor, Senior Vice President at LG Electronics, communicated the company’s commitment to addressing the issue directly. In a statement to KrebsOnSecurity, Taylor confirmed that LG was actively working with app developers to remove the residential proxy functionality from their applications on the webOS platform. He underscored the seriousness of the situation by stating that developers who fail to comply with these directives will face the suspension of their apps.
"A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor stated. "If this option is not removed, these apps will be suspended."
Taylor further emphasized LG’s dedication to preventing the proliferation of residential proxy networks within its smart TV applications moving forward. He assured that the company’s app review process is undergoing significant enhancement to ensure future compliance. "As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs," Taylor added in his emailed statement. This proactive stance from LG signals a significant shift in their platform governance and a commitment to safeguarding user interests.
The Business of Residential Proxies and App Monetization
The integration of residential proxy SDKs into smart TV apps is primarily driven by monetization strategies for app developers. Companies that operate residential proxy networks offer developers financial incentives to embed their SDKs. These SDKs transform the user’s device into a proxy node, which is then rented out to paying customers. These customers, often businesses or researchers, utilize these proxy networks to access the internet as if they were originating from the residential IP addresses of the proxy users.
Spur’s research uncovered that these proxy SDKs were not limited to niche or complex applications. They were found bundled with a surprisingly diverse range of software, including seemingly innocuous applications like Pac-Man, screensavers, and file utility tools. This broad integration made it difficult for consumers to identify or avoid apps that might compromise their privacy and bandwidth.
Bright Data’s Defense and Industry Practices
A significant player identified in Spur’s report was Bright Data, a prominent residential proxy network. According to Spur’s findings, Bright Data’s SDKs were the most prevalent across both LG and Samsung smart TV platforms.

In a statement provided to KrebsOnSecurity, Bright Data defended its operations, asserting that its network is built on principles of consent and responsibility, and that it adheres to the terms of service set by manufacturers like LG and Samsung. "Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC," the company stated. "We remain committed to an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain."
Bright Data and other proxy providers named in Spur’s report maintain that they implement stringent "know-your-customer" (KYC) processes to verify the legitimacy of their service users. These customers are often engaged in content scraping activities. Furthermore, these proxy companies claim to employ technological measures designed to prevent their service customers from interacting with or controlling other devices on the proxy user’s local network. This is a crucial point, as the potential for unauthorized access to a user’s local network is a significant privacy and security concern.
The Broader Implications for Consumer Devices
Spur’s argument extends beyond the mere existence of residential proxy networks. The firm contends that the core issue lies in the widespread embedding of these SDKs into devices that consumers do not typically perceive as computers and are not equipped to scrutinize for such functionalities. Smart TVs, once solely for entertainment, have evolved into sophisticated computing devices, yet consumer understanding of their underlying technical capabilities often lags behind.
Trevor Sutter of Spur articulated this concern, stating, "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight." He further highlighted the amplified risk when consent is obtained from individuals within a household who may not fully comprehend the implications or should not be the sole arbiters of such permissions, such as minors. The ease with which consent can be inadvertently given, or overridden by other users, presents a significant ethical and security challenge.
The implications of this practice are far-reaching. Beyond potential bandwidth theft and increased internet costs for users, the presence of a residential proxy can inadvertently expose a user’s IP address to potentially malicious actors. If a proxy user engages in illegal activities, the originating IP address could be traced back to the unsuspecting consumer whose device is being used as a proxy. This could lead to unwarranted investigations or legal repercussions for innocent individuals.
A Pattern of Questionable Partnerships
LG’s move to address the residential proxy issue comes shortly after the company faced criticism for another controversial partnership. Earlier this week, the YouTube channel Gamers Nexus highlighted that certain high-end LG LCD monitors automatically install an application that promotes paid McAfee antivirus subscriptions. This application, promoted through Windows Update without explicit user approval, has raised concerns about pre-installed bloatware and potentially intrusive software installations on consumer hardware.
This second instance of questionable pre-installation practices on LG devices further fuels the conversation about how major technology companies are integrating third-party software and services onto their products. While the residential proxy issue relates to app store content and user data, the McAfee promotion involves software drivers and system-level installations, suggesting a broader pattern of partnerships that may not always prioritize user transparency and control.
The Path Forward: Enhanced Scrutiny and User Awareness
LG’s commitment to suspending apps with residential proxy functionality marks a positive step towards enhancing the security and privacy of its smart TV users. However, the incident underscores the need for a more robust and transparent app vetting process across the entire smart TV industry. Consumers, in turn, need to be more vigilant about the applications they download and the permissions they grant.
The integration of sophisticated technologies into everyday consumer devices like smart TVs brings with it a new set of responsibilities for both manufacturers and users. As these devices become more interconnected and integral to our digital lives, ensuring their security and respecting user privacy must remain paramount. The ongoing dialogue between security researchers, manufacturers, and consumers will be crucial in shaping a more secure and transparent future for the Internet of Things. The industry must move towards models that prioritize user consent, clear communication, and robust oversight, ensuring that the convenience of smart technology does not come at the unacceptable cost of privacy and security.







