LG Electronics to Purge Smart TV Apps Using Residential Proxy SDKs Following Security Concerns Over Hijacked Network Traffic

LG Electronics USA has announced a definitive plan to suspend and remove any applications from its smart TV ecosystem that incorporate software designed to transform consumer devices into residential proxy nodes. This move, confirmed this week by high-ranking officials at the home appliance giant, represents a major shift in the company’s stance toward third-party app monetization strategies. The decision follows a series of alarming reports from cybersecurity researchers who discovered that a significant portion of the software available on major smart TV platforms was secretly or semi-secretly utilizing the internet connections of unsuspecting homeowners to route third-party traffic.
The crackdown comes in the wake of a detailed investigation by the security firm Spur, which highlighted the pervasive nature of residential proxy software development kits (SDKs) within the smart TV app landscape. According to Spur’s findings, more than 42 percent of the games and utilities available for download on LG’s webOS store contained code that allowed unknown third parties to use the TV as a relay point for internet traffic. This practice, while often framed as a "value exchange" by developers and proxy providers, has raised significant concerns regarding network security, user privacy, and the potential for household devices to be unwittingly recruited into botnets used for cyberattacks or large-scale data scraping.
The Scale of the Proxy SDK Problem
The research conducted by Spur, which was initially highlighted earlier this month, painted a troubling picture of the current state of smart TV app stores. By analyzing the network behavior and codebases of thousands of applications, researchers found that the issue was not isolated to a few rogue developers but was a systemic trend across the industry. While LG’s webOS showed the highest prevalence, with nearly half of its apps affected, Samsung’s Tizen operating system was not far behind, with over 25 percent of its applications containing similar proxy-sharing components.
Residential proxies are highly sought after by various entities because they provide IP addresses associated with real home internet connections rather than data centers. This makes the traffic originating from these proxies much harder for websites and security systems to block. While there are legitimate uses for such networks—such as price comparison, market research, and localized content testing—they are also frequently utilized for less savory activities, including credential stuffing, bypassing geographical restrictions on streaming services, and masking the origins of malicious cyber activity.
In the context of a smart TV, these SDKs turn the device into an "always-on" node. Unlike a smartphone, which may move between networks or be turned off, a smart TV is typically connected to a home’s Wi-Fi 24/7. This makes it an ideal target for proxy providers looking to maintain a stable and reliable network of residential IP addresses to rent out to their clients.
LG’s Official Stance and Enforcement Timeline
Responding to the findings, John Taylor, Senior Vice President at LG Electronics USA, clarified the company’s position in a statement provided to KrebsOnSecurity. Taylor emphasized that the use of LG hardware as a conduit for residential proxy networks was never an authorized or intended function of the webOS platform.
"A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor stated. He further issued an ultimatum to the developer community, noting that if the offending SDKs are not removed promptly, the applications will face immediate suspension from the LG Content Store.
The company has already begun a comprehensive review of its current app catalog. According to Taylor, this evaluation process is "well underway," and the company is taking steps to ensure that future submissions are scrutinized more heavily for these types of hidden functionalities. By strengthening the evaluation process, LG aims to prevent the re-introduction of these SDKs under different guises, thereby protecting the integrity of the user experience and the security of the consumer’s home network.
The Economics of "Free" Apps
The proliferation of proxy SDKs is driven primarily by the economics of the "freemium" app model. Developers of simple games, screensavers, and utility apps often struggle to monetize their products through traditional means, such as direct sales or intrusive banner ads. Proxy providers, such as Bright Data (formerly Luminati), offer an alternative: they pay developers a fee to include their SDK in the app.
In many cases, the user is presented with a choice upon opening the app. For example, a version of the classic game Pac-Man discovered on the LG store offered users a binary choice: they could either agree to view advertisements while playing or "share" their device’s idle internet resources to remove ads. For many users, particularly those who do not understand the technical implications of "sharing resources," the latter option seems like a harmless way to enjoy a free game.

However, security experts argue that this consent is often illusory. Trevor Sutter of Spur noted that a one-time prompt buried in a TV app is a poor substitute for meaningful transparency. "The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors," Sutter explained. Furthermore, once a user clicks "agree," the TV remains a proxy node indefinitely, often continuing to route traffic in the background even when the app is not actively being used.
Responses from the Proxy Industry
Bright Data, identified as one of the primary providers of these SDKs, defended its business model in a statement, asserting that its network is built on the principles of consent and responsibility. The company claimed that its practices are fully compliant with the terms of service set by platform holders like LG and Samsung.
"Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC," Bright Data stated. The company argued that its services are essential for a "transparent internet," allowing researchers and businesses to access public data without being unfairly blocked by automated systems.
While proxy providers claim to use "know-your-customer" (KYC) protocols to prevent abuse, security researchers remain skeptical. The technical reality is that once a device becomes a proxy node, the owner of that device has very little visibility into what traffic is passing through their network. If a customer of the proxy service uses the node to engage in illegal activity, the IP address recorded by the victim will be that of the innocent homeowner, potentially leading to legal complications or the blacklisting of their home IP by various internet services.
Broader Implications for IoT Security
The crackdown by LG highlights a growing tension in the Internet of Things (IoT) ecosystem. As everyday objects become "smart," they also become targets for monetization strategies that bypass traditional consumer awareness. The incident serves as a reminder that smart TVs are, in essence, powerful computers with significant network capabilities, yet they are rarely managed or audited with the same level of care as a laptop or smartphone.
The security risks extend beyond mere bandwidth consumption. There are documented cases where proxy SDKs have been leveraged to probe the local networks of users. Because the TV is "inside" the home firewall, a compromised or malicious proxy component could potentially communicate with other devices on the same Wi-Fi network, such as security cameras, network-attached storage (NAS) drives, or personal computers. While companies like Bright Data claim to have countermeasures against such "lateral movement," the mere existence of the capability remains a significant red flag for security professionals.
A Pattern of Questionable Partnerships
While LG’s move to ban proxy SDKs has been welcomed by the cybersecurity community, the company has recently faced criticism for other software-related practices. Just as the proxy news was breaking, the hardware review channel Gamers Nexus revealed that certain high-end LG LCD monitors were automatically installing McAfee security software on users’ Windows PCs via driver updates.
The software, which promotes paid antivirus subscriptions, was reportedly installed through Windows Update without a clear approval prompt from the user. This "bloatware" approach has led some critics to suggest that LG is aggressively seeking new revenue streams through software partnerships, sometimes at the expense of the user experience and system cleanliness. The juxtaposition of banning proxy SDKs on TVs while pushing unwanted antivirus software on monitors suggests a complex and sometimes contradictory corporate strategy regarding third-party software integrations.
Looking Ahead: The Future of Smart TV Apps
LG’s decision is likely to put pressure on other smart TV manufacturers, most notably Samsung, to follow suit. As the two largest players in the global smart TV market, their policies set the standard for the industry. If Samsung remains a haven for proxy SDKs while LG cleans up its store, it could create a significant differentiator in terms of privacy and security.
For developers, the ban represents the loss of a passive revenue stream, which may lead to a resurgence of traditional advertising or a shift toward subscription-based models for even simple apps. For consumers, the move is a victory for transparency, ensuring that the "centerpiece of the living room" remains a tool for entertainment rather than a silent participant in a global shadow network of internet traffic.
As the review process continues, LG users are encouraged to check their installed apps and be wary of any software that requests permission to share "idle resources" or "internet bandwidth." In the evolving landscape of the smart home, the price of "free" is increasingly being measured in privacy and network integrity.







