LG Electronics to Suspend Smart TV Apps Exploiting Devices as Residential Proxy Nodes

LG Electronics USA has announced a significant policy shift aimed at purging its smart TV ecosystem of applications that covertly or overtly transform consumer hardware into residential proxy nodes. The decision follows a series of alarming reports from cybersecurity researchers indicating that a staggering percentage of applications available on the LG webOS platform—and to a lesser extent, Samsung’s Tizen OS—incorporate software development kits (SDKs) designed to rent out a user’s internet connection to third parties. This move marks a critical turning point in the governance of Internet of Things (IoT) devices, as manufacturers begin to grapple with the security and privacy implications of the "monetization at any cost" culture prevalent in the app development industry.
The controversy began to gain significant traction in early July when the security firm Spur released a detailed analysis of the smart TV app landscape. According to Spur’s research, more than 42 percent of the games and utility applications available for download on LG’s webOS store contained embedded residential proxy SDKs. These SDKs allow unknown third parties to route their internet traffic through the user’s home network, effectively turning the television into an "always-on" gateway for global internet traffic. While the practice is often framed as a way for developers to offer "ad-free" experiences, the security risks and potential for abuse have prompted LG to take decisive action.
The Mechanics of Residential Proxy SDKs
To understand the gravity of LG’s decision, it is necessary to examine how residential proxies operate and why they have become a favored tool for both legitimate businesses and malicious actors. A residential proxy is an intermediary that uses an IP address assigned by an Internet Service Provider (ISP) to a homeowner. Unlike data center proxies, which are easily identified and blocked by websites, residential proxies appear as legitimate domestic traffic. This makes them highly valuable for activities such as web scraping, bypassing geo-restrictions, and market research.
However, the demand for these IP addresses has created a secondary market where app developers are incentivized to turn their users’ devices into nodes within a larger proxy network. Companies like Bright Data, which was identified in the Spur report as a primary provider of these SDKs, pay developers to include their code in popular apps. When a user installs a game or a screensaver, they are often presented with a choice: view advertisements or "share" their idle internet resources. In many cases, users—particularly children or those less tech-savvy—may agree to these terms without understanding that they are essentially allowing a stranger to use their home network as a digital mask.
Findings from the Spur Research Report
The data provided by Spur highlights a systemic issue within the smart TV app marketplace. The investigation found that the prevalence of these SDKs is not limited to obscure or "shady" applications. Instead, they were discovered in everything from basic file utilities and system tools to classic games like Pac-Man. The report noted that while LG’s webOS had the highest concentration of these components at 42 percent, Samsung’s Tizen operating system was not far behind, with more than 25 percent of its apps containing similar proxy-sharing capabilities.
The primary concern raised by Spur is the lack of "meaningful transparency." While some apps provide a consent prompt, these are often buried in legal jargon or presented in a way that minimizes the perceived risk. Furthermore, once consent is given, the TV remains a proxy node indefinitely, often operating in the background even when the app is not actively being used. This "always-on" nature of smart TVs makes them ideal candidates for proxy networks, as they are rarely powered off and maintain a stable connection to the home Wi-Fi.
LG’s Official Response and Enforcement Strategy
Responding to the findings, LG Senior Vice President John Taylor provided a clear ultimatum to the developer community. Speaking with security news outlets, Taylor emphasized that residential proxy networks are not an intended or authorized use for LG smart TVs. He confirmed that the company is currently in the process of reviewing all submitted applications on the webOS platform to identify those utilizing these SDKs.
"LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor stated. "If this option is not removed, these apps will be suspended."
This proactive stance suggests a shift in how LG views its responsibility as a platform gatekeeper. By threatening suspension, LG is forcing developers to choose between their monetization partnerships with proxy providers and their access to the millions of households that use LG smart TVs. Taylor also noted that the company is strengthening its evaluation process for all future app submissions to ensure that residential proxy SDKs do not find their way back onto the platform under different guises.

Security Implications and the Risk of Lateral Movement
Beyond the ethical concerns of transparency and consent, the technical risks of hosting a proxy node are substantial. When a device acts as a residential proxy, the owner has no control over the content being routed through their network. If a third party uses that connection to engage in illegal activities—such as launching cyberattacks, distributing illicit material, or scraping sensitive data—the digital trail leads directly back to the unsuspecting homeowner’s IP address. This can result in the homeowner being blacklisted by websites, flagged by their ISP, or even becoming the subject of law enforcement investigations.
Furthermore, there is the risk of "lateral movement" within the home network. Security researchers have long warned that once a device on a local network is compromised or running unauthorized third-party code, it can serve as a bridge to other connected devices. While proxy providers like Bright Data claim to have technological countermeasures to prevent their customers from interacting with other devices on the proxy user’s network, these safeguards are not foolproof. The history of the "Kimwolf" botnet and similar threats has shown that vulnerabilities in IoT devices are frequently exploited to stalk local networks and steal data from computers, smartphones, and security cameras sharing the same Wi-Fi.
A Growing Pattern of Privacy and Bloatware Concerns
The crackdown on proxy SDKs comes at a time when LG is already facing scrutiny for other questionable software practices. Recently, the hardware community was alerted to a partnership between LG and McAfee that involves the automatic installation of security software on high-end LCD monitors. According to reports from technical analysts and the YouTube channel Gamers Nexus, certain LG monitors trigger a Windows Update that installs a McAfee "utility" app without a clear approval prompt from the user.
This app primarily serves as a promotional tool for paid antivirus subscriptions. Critics argue that this represents an overreach of the "driver update" system, using it as a delivery mechanism for "bloatware" or "crapware." When viewed alongside the proxy SDK issue, a picture emerges of a hardware giant struggling to balance the desire for recurring software revenue with the need to protect the user experience and device integrity.
The Role of Consent and the Vulnerability of Minors
One of the most poignant arguments made by Spur’s Trevor Sutter involves the validity of consent in a household setting. Smart TVs are communal devices often used by multiple family members, including minors. If a child playing a game on the TV clicks "Accept" on a prompt they do not understand, they have effectively compromised the security of the entire household’s internet connection.
"A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight," Sutter wrote in the Spur report. The argument is that for a device as central to the home as a television, the default state should be one of maximum security, and the "opt-in" for such invasive features should require a level of authentication that a child or a guest cannot provide.
Broader Impact on the IoT Industry
LG’s decision to purge proxy nodes could have a ripple effect across the entire IoT industry. As smart refrigerators, thermostats, and even light bulbs become more computationally capable, they become more attractive to proxy providers looking to expand their networks. If LG successfully cleans its app store, pressure will likely mount on Samsung, Sony, and other manufacturers to follow suit.
The situation also highlights the need for better industry-wide standards regarding what constitutes an "acceptable" monetization strategy for IoT apps. While developers certainly deserve to be compensated for their work, the current model of turning consumer hardware into a revenue-generating node for third-party traffic is increasingly being viewed as a violation of the "implied contract" between the manufacturer and the buyer.
Chronology of Events
- Early 2024: Security firm Spur begins an intensive audit of smart TV application stores, focusing on the prevalence of residential proxy SDKs.
- July 2, 2024: Spur publishes its findings, revealing that 42% of LG webOS apps and 25% of Samsung Tizen apps function as proxy nodes.
- July 10-15, 2024: Media outlets, including KrebsOnSecurity, reach out to LG and Samsung for comment on the research.
- July 18, 2024: LG Senior VP John Taylor issues a formal statement confirming that the company will suspend any apps that do not remove the residential proxy SDKs.
- Late July 2024: LG begins a comprehensive review of its app store, notifying developers of the new enforcement policy.
- Ongoing: Security researchers continue to monitor the Samsung Tizen store to see if similar enforcement actions will be taken by the South Korean rival.
Conclusion and Future Outlook
The initiative by LG Electronics to remove residential proxy nodes from its smart TVs is a necessary step toward reclaiming the security of the modern living room. For too long, the "smart" in smart devices has been leveraged more for the benefit of advertisers and data brokers than for the consumers who purchase the hardware. By taking a hard line against these SDKs, LG is signaling that it prioritizes the integrity of its platform over the niche monetization needs of developers who rely on opaque traffic-sharing schemes.
However, the battle for IoT security is far from over. As long as there is a lucrative market for residential IP addresses, developers and proxy providers will continue to look for ways to bypass platform restrictions. The challenge for LG and its peers will be to maintain a rigorous and evolving vetting process that stays ahead of these tactics. For consumers, the message is clear: even a device as seemingly benign as a television requires a degree of digital vigilance. The "free" app that asks for permission to use your internet connection might be a bargain that costs much more than it appears.






