Samsung Will Ban Smart TV Apps Containing Residential Proxy Software

A Samsung Smart TV app can pass review, remain dormant for months, and later be remotely activated as part of a residential proxy network.

Samsung Will Ban Smart TV Apps Containing Residential Proxy Software

Samsung Will Ban Smart TV Apps Containing Residential Proxy Software

A Samsung Smart TV app can pass review, remain dormant for months, and later be remotely activated as part of a residential proxy network.

Samsung told TechCrunch that it will ban Smart TV apps containing residential proxy software after security researchers found that some apps could be remotely converted into proxy nodes. The software allows third parties to route internet traffic through users’ home connections..

The issue centers on certain software development kits, or SDKs, that developers can add to apps. Once activated, the code can use a television’s internet connection as part of a residential proxy network.

The findings have renewed concerns about app-store reviews, platform trust, and user privacy because an app’s behavior can change long after it has been approved.

What exactly went wrong

Samsung’s policy change comes after LG adopted a similar ban following separate research that uncovered residential proxy software in some Smart TV apps.

To investigate, researchers at the Norwegian cybersecurity firm Mnemonic obtained root access to a Samsung Smart TV, granting them low-level control over the device. As they analyzed multiple apps, they discovered an app bundled with Bright Data’s SDK.

Software development kits, or SDKs, are packages of prewritten code that developers use to add features without building them from scratch. Mnemonic researchers found one Samsung Smart TV app containing an SDK from residential proxy provider Bright Data.

It is also worth noting that the use of proxies isn’t illegal in many standard cases. However, because residential IP addresses are often highly trusted, these proxy services have found ways to route internet traffic using residential IPs, and what better devices to use for this than Smart TVs.

The researchers found that the SDK remained dormant within the apps until each application contacted remote servers to retrieve configuration files at launch. That dormancy allowed the apps, whose code appears clean, to potentially evade detection from Samsung during the app review process.

More importantly, it was discovered that these proxy services asked TV viewers for consent before using their IPs for proxy routing. But the researchers argue that most users would simply grant consent due to a lack of knowledge about what it actually is, especially if the viewer is a child.


Advertisement

A reminder to trust, but verify

One detail from Mnemonic’s research stood out: one of the apps embedding the proxy SDKs had previously been featured in Samsung Editor’s Choice. The finding shows that marketplace badges and editorial promotion do not guarantee that an app’s third-party components will remain benign over time.

The finding also highlights a broader challenge facing app stores. Modern applications are increasingly built using third-party SDKs. These SDKs are typically different from an app developer’s written code. The incident suggests that conventional app reviews may struggle to account for third-party components whose behavior depends on remote configuration after approval.

Adding to the challenge is remote configuration. As Mnemonic’s research showed, developers can turn certain features on or off after an app has been installed, without necessarily publishing a new version for review. The same remote-configuration mechanism could make it difficult for platform owners to know whether an approved app will behave the same way after installation.

That effectively makes it harder for platform owners to guarantee that the software users are running is identical to the one originally approved.

For users, official app stores remain among the strongest security signals. Yet, this research challenges that assumption, leaving non-technical users who rely on developer labels and marketplace trust in a complex position.

The most straightforward recommendation is to stick to apps from reputable developers, pay attention to the permissions and prompts they request, and remove apps you no longer use or trust.

Other News: Claude Opus 5 topped a simulated vending-business benchmark while fabricating supplier bids, breaking agreements, and limiting refunds.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.