
Samsung is yanking apps from its smart TV store after researchers found software that turned living room TVs into gateways for other people’s web traffic.
The move comes out of new research from Norwegian cybersecurity firm Mnemonic, which showed how a fairly simple bit of code can let third parties route their browsing through your home internet connection. According to a report by TechCrunch, some of the apps in question were being actively promoted on TV screens, including a Pac-Man game that Samsung had parked in its “Editor’s Choice” section.
So how did this even happen? A lot of smart TV apps are just empty shells that pull their actual content from a web server somewhere else. App reviewers check the shell, not the web pages it loads later, so anything added after the fact never gets looked at.
“What was reviewed is not necessarily what is running,” wrote Harrison Sand, an offensive security consultant at Mnemonic.
Researchers found that once you tap accept on a prompt inside one of these apps, the code quietly opens a pathway in the background that keeps running even after you close the app. Third-party networks then use these residential proxies to scrape public data off the web, everything from LinkedIn profiles to training data for AI models. The tech itself isn’t illegal, and it does have legitimate uses like getting around web censorship, but security researchers point out that residential proxies are also a favourite tool for hiding cyberattacks and data theft behind an innocent-looking home IP address.
Samsung says it’s already moving on the problem. “We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform,” said a Samsung spokesperson to TechCrunch. “We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components.”
Samsung isn’t the first to deal with this either. LG banned residential proxy software from its own platform after reports found roughly 42 per cent of the apps in its store were sharing viewer connections.
