LG Electronics Initiates Crackdown on Smart TV Apps Harboring Residential Proxy SDKs Following Security Research

LG Electronics USA has announced a significant policy shift regarding its webOS smart TV platform, pledging to suspend and remove applications that incorporate residential proxy software development kits (SDKs). The decision follows a series of alarming reports from cybersecurity researchers indicating that a substantial portion of the applications available on major smart TV platforms are being used to transform consumer hardware into "zombie" proxy nodes. This move marks a critical turning point in the management of Internet of Things (IoT) ecosystems, as manufacturers face increasing pressure to protect the privacy and network integrity of their customers.
The controversy erupted in early July when the cybersecurity firm Spur published a detailed examination of the prevalence of residential proxy SDKs in the smart TV app marketplace. According to Spur’s data, more than 42 percent of applications available for download on LG’s webOS store contained embedded code that allowed unknown third parties to route internet traffic through the user’s television. The research also highlighted similar issues within Samsung’s Tizen operating system, where more than 25 percent of apps were found to possess these hidden proxy components.
The Mechanics of Residential Proxy Monetization
A residential proxy network is a system where the IP addresses of home internet users are sold or rented to third parties. These third parties use the residential IPs to mask their own identities, often to perform activities such as large-scale web scraping, bypassing geographic restrictions on streaming content, or conducting market research. While some uses are legitimate, residential proxies are also highly sought after by cybercriminals for launching credential stuffing attacks, ad fraud, and distributed denial-of-service (DDoS) operations, as traffic coming from a home IP is less likely to be flagged as suspicious by security filters.
For app developers, residential proxy SDKs represent an alternative monetization strategy. In many cases, developers of "free" apps—ranging from simple games like Pac-Man to utility software and screensavers—integrate these SDKs into their products. The proxy provider then pays the developer based on the number of active users or the amount of bandwidth routed through the devices. This model allows developers to generate revenue without relying solely on traditional advertising or in-app purchases, but it often comes at the expense of the user’s network security and bandwidth.
Official Response from LG Electronics
Responding to the findings, LG Senior Vice President John Taylor provided a statement to KrebsOnSecurity, clarifying the company’s stance on the unauthorized use of its hardware for proxy networking. Taylor emphasized that the intended use of an LG smart TV does not include serving as a node for third-party internet traffic.
"A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor stated. He further warned that non-compliance would result in immediate repercussions for developers, noting, "If this option is not removed, these apps will be suspended."
The company has reportedly initiated a comprehensive review of its entire application library. This evaluation process is intended not only to purge existing apps containing these SDKs but also to strengthen the vetting process for future submissions. LG’s commitment to "platform quality and the user experience" suggests a shift toward a more closed and strictly regulated ecosystem, similar to the "walled garden" approach seen in mobile operating systems.
The Industry Perspective: Bright Data and the Question of Consent
Among the proxy providers identified in Spur’s research, Bright Data emerged as a primary player. The company maintains that its operations are entirely legal and based on a model of informed consent. In a statement addressing the research, Bright Data asserted that its network is built on "consent and responsibility" and operates within the terms of service set by manufacturers like LG and Samsung.
"Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC," the company stated. Bright Data argues that its services facilitate an "open, transparent internet" by allowing legitimate businesses and researchers to access public data.
However, security experts argue that the concept of "consent" in this context is often flawed. Trevor Sutter of Spur pointed out that a one-time prompt buried within a TV app is often insufficient for meaningful transparency. Furthermore, the risk is exacerbated in households where minors or non-technical users may inadvertently grant permission for the device to be used as a proxy node without understanding the long-term implications for the home network’s security.

Security Implications and Lateral Movement Risks
The primary concern for cybersecurity professionals is not merely the consumption of bandwidth, but the potential for "lateral movement" within a home network. When a device like a smart TV becomes a proxy node, it essentially opens a gateway. While proxy providers claim to use technological countermeasures to prevent customers from interacting with other devices on the user’s local network, the presence of such a connection remains a significant risk.
If a vulnerability exists in the proxy SDK or the way it is implemented, a malicious actor could theoretically exploit that connection to scan the user’s local network for other vulnerable devices, such as Network Attached Storage (NAS) drives, personal computers, or smart home controllers. This turns the television—a device often left on or in standby mode 24/7—into a permanent foothold for potential attackers inside the home’s digital perimeter.
Chronology of the Controversy
The crackdown by LG follows a timeline of increasing scrutiny regarding IoT security and "shadow" monetization:
- Early 2024: Security firms begin noticing a spike in residential proxy traffic originating from non-traditional computing devices, including smart refrigerators and televisions.
- January 2024: Reports emerge regarding the "Kimwolf" botnet, which specifically targeted IoT devices to create a sprawling network for malicious traffic routing.
- July 2, 2024: KrebsOnSecurity reports on the FBI’s seizure of the NetNut proxy platform and the dismantling of the Popa botnet, highlighting the legal risks associated with proxy networks.
- July 2024: Spur releases its groundbreaking report identifying the 42 percent saturation of proxy SDKs in the LG webOS store.
- Late July 2024: LG Electronics USA officially announces its plan to purge these apps and update its developer guidelines.
Contextual Background: LG’s Software Partnerships
The decision to clean up the webOS store comes at a time when LG is already facing criticism for other software-related practices. Recently, the popular hardware review channel Gamers Nexus highlighted a controversial partnership involving LG’s high-end LCD monitors.
According to the report, certain LG monitors automatically install a McAfee security application on the user’s Windows PC through a software driver delivered via Windows Update. This installation occurs without an explicit approval prompt from the user and serves primarily to promote paid antivirus subscriptions. Critics argue that this "bloatware" approach undermines consumer trust and suggests a corporate culture that prioritizes auxiliary revenue streams over the user experience.
The contrast between LG’s proactive stance on proxy SDKs and its aggressive promotion of McAfee products suggests a complex internal struggle within the company. While LG is moving to secure its TV platform from external proxy providers, it continues to explore controversial monetization methods in its monitor division.
Broader Impact on the Smart TV Industry
LG’s move is likely to put pressure on other major players in the smart TV market, most notably Samsung. As the manufacturer of the Tizen OS, which also showed a high prevalence of proxy SDKs in Spur’s research, Samsung has yet to announce a similarly sweeping crackdown. If LG successfully purges its store, it could set a new industry standard for "Security by Design" in the smart home space.
The situation also highlights a growing regulatory gap. Currently, there are few federal regulations in the United States specifically governing the use of residential proxy SDKs in consumer electronics. As IoT devices become more integrated into daily life, consumer advocacy groups are calling for stricter "Dark Pattern" legislation to prevent companies from using confusing interfaces to gain consent for invasive data practices.
Conclusion and Future Outlook
The removal of residential proxy SDKs from the LG webOS platform is a necessary step toward securing the modern home. For consumers, the message is clear: "free" applications often carry hidden costs that extend beyond simple advertising. For the industry, LG’s decision serves as a warning that the era of unregulated "shadow monetization" in the IoT space may be coming to an end.
As LG proceeds with its audit, the tech community will be watching closely to see how the company balances its need for revenue with its responsibility to protect its customers. The success of this initiative will depend on LG’s ability to maintain a rigorous and transparent vetting process for developers, ensuring that the smart TV remains a center for entertainment rather than a gateway for unauthorized network activity.







