LG Electronics to Purge Smart TV Apps Using Residential Proxy SDKs Following Security Research

LG Electronics USA has officially announced a sweeping initiative to identify and suspend applications on its smart TV platform that secretly or overtly transform consumer hardware into residential proxy nodes. This strategic move follows a series of alarming reports from cybersecurity researchers indicating that a significant portion of the applications available on the LG webOS store were being used to route third-party internet traffic through residential connections. By turning televisions into always-on proxy servers, these apps effectively allow unknown actors to mask their digital footprints using the IP addresses of unsuspecting homeowners.
The decision marks a critical turning point in the governance of smart TV ecosystems, which have increasingly become targets for monetization schemes that bypass traditional advertising models. As smart TVs evolve from simple display units into sophisticated, internet-connected computing hubs, the security community has raised concerns regarding the lack of transparency in how third-party developers utilize the hardware’s processing power and network bandwidth.
The Catalyst: The Spur Research Report
The impetus for LG’s crackdown was a detailed investigative report published by the security firm Spur, which specializes in tracking proxy networks and digital identity. In early July, Spur released findings that sent shockwaves through the IoT (Internet of Things) security sector. According to their data, more than 42 percent of the games and utility applications available for download on the LG webOS store contained residential proxy software development kits (SDKs).
These SDKs are designed to integrate a device into a global network of proxy nodes. Once an app containing such an SDK is installed and launched, the device becomes a "hop" for internet traffic generated by customers of proxy service providers. While these services are often marketed for legitimate purposes—such as price comparison, market research, or bypassing geographic content restrictions—they are also highly prized by malicious actors for activities like credential stuffing, ad fraud, and distributed denial-of-service (DDoS) attacks.
Spur’s research did not limit its scope to LG. The firm also examined Samsung’s Tizen operating system, the leading competitor in the smart TV market. The investigation revealed that more than 25 percent of the apps available for Samsung televisions featured similar residential proxy components. However, the prevalence in the LG ecosystem was notably higher, prompting immediate scrutiny of LG’s app review and approval processes.
Understanding the Residential Proxy Monetization Model
The inclusion of proxy SDKs in seemingly harmless applications is primarily driven by monetization. App developers, particularly those offering free games, screensavers, or file utilities, often struggle to generate revenue through traditional means. Residential proxy providers offer an alternative: they pay developers a fee to bundle their SDKs within the app’s code.
In many cases, the user is presented with a choice upon opening the app. For example, a version of the classic game "Pac-Man" or a system utility might offer the user two options: view frequent advertisements or agree to "share" a portion of their internet connection to support the developer. If the user selects the latter, their TV becomes a residential proxy node. Because smart TVs are frequently left in a "standby" mode rather than being fully powered off, they represent an ideal target for proxy networks, providing an "always-on" connection that can be utilized 24/7.
The primary provider identified in the Spur report was Bright Data, a major player in the proxy and data collection industry. Bright Data and its competitors argue that their services are built on a foundation of informed consent and rigorous "Know Your Customer" (KYC) protocols. They claim to implement technological safeguards to ensure that their customers cannot access the local networks of the proxy hosts or interact with other devices in the home.
Official Response from LG Electronics
Responding to the findings, LG Electronics USA has taken a firm stance against the practice. John Taylor, Senior Vice President at LG, stated that residential proxy networks are not a sanctioned or intended use for the company’s smart TVs. In a statement provided to security analysts, Taylor confirmed that the company is actively working with developers to purge these options from the webOS platform.
"A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor said. He further clarified that the company is issuing an ultimatum: developers who do not remove the proxy SDKs will face immediate suspension from the LG app store.
LG has indicated that its review process is already "well underway." The company intends to strengthen its evaluation criteria for all future developer submissions to prevent the re-emergence of these SDKs. This involves a more granular analysis of the code and the secondary functions of applications that may appear benign on the surface.

Security and Privacy Implications for Consumers
The presence of residential proxies on home devices presents several layers of risk that extend beyond simple bandwidth consumption. Cybersecurity experts, including Trevor Sutter of Spur, argue that the "consent" model used by these apps is fundamentally flawed.
One of the primary concerns is the lack of ongoing transparency. While a user might agree to a prompt once, they are rarely reminded that their device is continuously acting as a gateway for foreign traffic. Furthermore, in many households, the person giving consent may not be the primary account holder or the individual responsible for the home’s cybersecurity. Minors, for instance, might agree to "share the connection" simply to get back to a game, without understanding the technical or legal implications of allowing third parties to use their home IP address.
From a legal and security standpoint, having one’s IP address associated with the traffic of unknown third parties is inherently risky. If a malicious actor uses a residential proxy to conduct illegal activities, the digital trail leads directly back to the innocent consumer’s home. While proxy providers claim to vet their clients, the history of the internet has shown that these networks are frequently abused.
Additionally, there is the "pivot" risk. Even if current SDKs are designed to isolate proxy traffic from the rest of the home network, vulnerabilities in the software could allow an attacker to move laterally. A compromised smart TV could potentially serve as a bridge to other sensitive devices on the same Wi-Fi network, such as laptops containing personal financial data or home security cameras.
Contextualizing the Move: LG’s Software Controversies
LG’s move to clean up its smart TV store comes at a time when the company is facing criticism for other software-related practices. Recently, the tech community has scrutinized LG for a partnership involving its high-end LCD monitors.
As reported by the hardware investigative channel Gamers Nexus, certain LG monitors have been found to automatically trigger the installation of McAfee security software on connected Windows PCs. This process occurs through Windows Update without an explicit approval prompt from the user, leading to accusations of "bloatware" being pushed through hardware drivers.
This incident, combined with the proxy SDK issue, highlights a growing tension between hardware manufacturers and consumers regarding the "monetization of the endpoint." As hardware margins thin, companies are increasingly looking toward software partnerships and data-driven revenue streams. However, as the LG smart TV situation demonstrates, when these partnerships compromise the security or integrity of the device, the resulting backlash can necessitate a rapid retreat and a re-evaluation of platform standards.
The Broader Impact on the Smart Home Industry
LG’s decision is likely to put pressure on other manufacturers to follow suit. Samsung, with a quarter of its Tizen apps affected by similar SDKs, has yet to announce a policy as definitive as LG’s. If LG successfully purges these SDKs, it could set a new industry standard for "clean" IoT ecosystems, potentially using security and privacy as a competitive advantage.
The situation also serves as a warning to the developer community. The "easy money" provided by proxy SDKs is becoming a high-risk proposition that could lead to permanent deplatforming. As major manufacturers like LG tighten their oversight, developers will need to find more transparent and less intrusive ways to monetize their content.
Conclusion and Future Outlook
The proactive measures taken by LG Electronics USA represent a necessary step in securing the modern smart home. By acknowledging that a television should remain a consumption device rather than a component of a global proxy infrastructure, LG is addressing a critical vulnerability in the IoT landscape.
However, the challenge remains significant. The sheer volume of apps and the evolving nature of SDK code mean that automated detection is not always foolproof. Ongoing vigilance from both manufacturers and independent security researchers will be required to ensure that smart TVs do not become the "weakest link" in residential cybersecurity.
For consumers, the takeaway is a reminder that in the era of the Internet of Things, every connected device—from a toaster to a 75-inch 4K television—is a computer. Users are encouraged to be wary of "free" apps that ask for unusual permissions and to regularly audit the applications installed on their smart devices. As LG moves forward with its suspension of non-compliant apps, the industry will be watching closely to see if this marks the beginning of a broader trend toward more ethical and secure smart device management.







