Samsung Smart TVs at Risk: Apps Found with Hidden Proxy Code
If you own a Samsung smart TV, you might want to pay attention to this. Recent security research has revealed that some popular Samsung smart TV apps contain hidden code that could turn your home network into a proxy for strangers. Yes, you read that right—your TV might be secretly sharing your internet connection with unknown third parties.
The findings come from Mnemonic, a Norwegian cybersecurity firm. They discovered that several apps, including a Pac-Man game that Samsung itself recommended and even featured in the TV's "Editor's Choice" section, were bundled with residential proxy code. This code, known as resproxies, can use your device's network connection as an exit node to route internet traffic for others.
Here's the unsettling part: even if you close the app, as long as the proxy components remain on your TV, it could keep participating in this network. Security consultant Harrison Sand, who led the research, explained that what you see during an app review isn't necessarily what actually runs. That means apps with risky code can slip into the smart TV ecosystem without raising red flags.
So, what exactly is residential proxy technology? It's not illegal by itself. In fact, AI companies often use such networks to collect public data from various locations for training their models. But here's the catch: because proxy traffic comes from real home networks, attackers could hide their tracks and use it for cyberattacks, data leaks, or bypassing security restrictions.
Mnemonic's analysis of network traffic suggests that some resproxy networks have already been used for large-scale scraping of LinkedIn user information and gathering AI training data. While it's not confirmed that all affected apps are malicious, the researchers warn that if server-side code changes, the risks could escalate quickly.
Samsung has responded by restricting new apps with residential proxy functions from registering and is implementing stricter developer policies to ban such SDKs. They're also cleaning up existing apps in their store that contain these components. This follows a similar move by LG, which banned related software after discovering that about 42% of apps in its store were connected to proxy networks.
This incident highlights a growing challenge for smart device platforms: how to balance the demand for AI data collection with user security. As the use of residential proxy networks expands, the question becomes—how do we protect our home networks while still enabling legitimate data gathering? It's a tricky balance, and one that consumers should be aware of.
For now, if you're a Samsung smart TV user, it might be wise to review your installed apps and consider removing any that seem suspicious. After all, your TV shouldn't be working for someone else without your knowledge.
Key Points
- Hidden Proxy Code: Several Samsung smart TV apps, including a recommended Pac-Man game, contain residential proxy code that could share your network with third parties.
- Security Risk: This code can turn your TV into a proxy node, potentially enabling cyberattacks or data leaks.
- Samsung's Response: Samsung is banning residential proxy SDKs and cleaning up its app store, following LG's similar action.
- Broader Implications: The incident underscores the tension between AI data collection and user privacy in the smart device ecosystem.