What the Research Found
On Monday, Norwegian cybersecurity firm Mnemonic published findings showing that a number of widely used Samsung smart TV applications include code that shares a homeowner's internet connection with outsiders. According to the research, this could expose millions of Samsung smart TVs to potential hijacking. App makers say these applications are present on more than one hundred million household televisions worldwide.
A Promoted Pac-Man Game Was Hiding Something
Bright Data is an Israeli firm whose proxy services claim to reach millions of residential networks globally. Bright Data also operates a storefront for datasets gathered with the help of smart TVs that act as exit points, pulling in bulk web data and often dodging anti-scraping defenses.
When Sand opened the Pac-Man game, the resproxy code loaded, but it did not immediately make the TV an exit node. It remained inactive until the user agreed to a consent screen; then it started running in the background and continued until the app was deleted.
Get the market news that matters in a five-minute read with Market Briefs, our free daily newsletter
After TechCrunch reached out, Samsung's response came in an emailed statement: "We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform." A Samsung spokesperson added: "We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components."
How the Proxy Scheme Works
The research paints a picture of several converging issues that let low-quality apps spread through Samsung's app store. Most of these programs are extremely stripped down, built from just a handful of code lines and intended only to pull in content from another site. Reviewers may check the small amount of code inside these apps, but they are not necessarily seeing the content that loads from the remote server. "What was reviewed is not necessarily what is running," wrote Sand, an offensive security consultant at Mnemonic.
These proxy networks are legal in many contexts. They can, for example, help people evade censorship by sending internet traffic through ordinary residential connections. AI companies also use resproxies to gather data from many websites at once for training their models.
Cybersecurity firms, however, say they have become known as tools that let hackers and spies conduct attacks and data theft while concealing their actions. Because the traffic appears to originate from an ordinary home and is usually encrypted, it is nearly impossible to decrypt and examine.
Sand rooted a Samsung smart TV's software, giving himself deep access to its internals; he then examined all traffic entering and leaving the device, including traffic from apps that shared the connection. According to Sand, what he observed was only a small fraction of the traffic flowing through Bright Data's network. Most of the traffic hinted that the resproxy service was involved in mass scraping of LinkedIn profiles and gathering AI training data.
Bright Data did not answer a request for comment.
Samsung and LG
Samsung isn't the only manufacturer responding. Last month, LG said it would forbid apps with resproxy software, after findings showed that roughly 42% of apps on LG's store made a television an endpoint in a proxy network.
Such proxy code is not limited to TVs; it also turns up in ordinary phone apps and devices such as digital photo frames and Android streaming boxes, causing those devices to share their home connection. Whenever such an app or device goes online, outsiders can pay to route traffic through it.
Join Market Briefs, our free daily newsletter, for a quick daily rundown of the markets
