In a significant move to bolster user privacy and security, LG Electronics USA has announced its intention to suspend all applications on its smart TV platform that facilitate the use of televisions as residential proxy nodes. This decisive action comes less than a month after a critical report by the security firm Spur revealed that a staggering 42% of apps available on LG’s webOS store were embedding software development kits (SDKs) that allowed third parties to route their internet traffic through unsuspecting users’ televisions. The findings highlighted a widespread vulnerability where everyday smart TVs were being transformed into always-on proxy servers, a practice LG now deems an "unintended use" for its devices.
The research, published on July 2nd, meticulously detailed the prevalence of these residential proxy SDKs across smart TV ecosystems. Spur’s investigation found that not only did over 42% of LG’s webOS apps contain these components, but also that more than a quarter of apps designed for Samsung’s Tizen operating system exhibited similar functionalities. This widespread integration raised serious concerns about user consent, data privacy, and the potential for malicious exploitation, as these SDKs effectively turn a user’s home internet connection into a relay point for unknown entities.
In direct response to these revelations, John Taylor, Senior Vice President at LG Electronics, communicated to KrebsOnSecurity that the company is actively collaborating with app developers to eradicate the residential proxy functionality from their applications on the webOS platform. Taylor emphatically stated, "A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform. If this option is not removed, these apps will be suspended." This firm stance underscores LG’s commitment to safeguarding its users from the risks associated with their devices being exploited for proxy services.
LG’s proactive approach extends beyond immediate remediation. Taylor assured that the company is dedicated to preventing the recurrence of such issues in the future. "As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs," Taylor elaborated in a written statement. This implies a more rigorous vetting process for all future app submissions to the webOS store, aiming to preemptively identify and reject applications that compromise user privacy.
The economic incentives behind the integration of residential proxy SDKs are clear. App developers, seeking novel revenue streams, can partner with residential proxy providers. These providers offer financial compensation to developers in exchange for embedding SDKs that transform user devices into proxy nodes, which are then leased to paying customers. Spur’s report revealed that these SDKs were found bundled with an array of applications, ranging from seemingly innocuous games like Pac-Man to utility software and even screensavers, suggesting a broad and often undisclosed integration strategy.

The report specifically identified Bright Data as a dominant player in the residential proxy SDK market across both LG and Samsung smart TVs. In a statement provided to KrebsOnSecurity, Bright Data defended its practices, asserting that its network operates on principles of "consent and responsibility" and adheres to the terms set by LG and Samsung. The company highlighted its user onboarding process, stating, "Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC." Bright Data further emphasized its commitment to a "transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain."
While proxy providers like Bright Data maintain that they implement stringent know-your-customer (KYC) protocols to verify the legitimacy of their clients’ activities, primarily focused on content scraping, and employ technical safeguards to prevent proxy users from accessing other devices on the host’s local network, security researchers remain concerned. Spur, in its analysis, argued that the fundamental issue lies not with the existence of residential proxy networks, but with their pervasive integration into devices that consumers do not perceive as full-fledged computers and are thus ill-equipped to monitor.
Trevor Sutter of Spur articulated the core of this concern: "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight. The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors." This highlights the inadequacy of often opaque and easily overlooked consent mechanisms in safeguarding vulnerable users.
LG’s decision to remove residential proxy SDKs from its app store is a welcome development, but it arrives amidst another controversy surrounding the company’s partnerships. Earlier this week, reports emerged detailing how LG’s high-end LCD monitors were found to be installing McAfee security software through driver installations, often without explicit user consent via Windows Update. This practice, exposed by the YouTube channel Gamers Nexus, further fueled scrutiny over LG’s approach to pre-installed software and partnerships that could potentially compromise user autonomy and digital security.
The update on July 22nd at 1:06 p.m. ET includes the statement from Bright Data, providing their perspective on the matter and their efforts to ensure responsible operation. This ongoing dialogue between tech giants, security researchers, and proxy service providers underscores the evolving landscape of digital privacy and the constant need for vigilance in an increasingly connected world. LG’s decisive action sets a precedent for other smart TV manufacturers and highlights the critical role of platform owners in policing their ecosystems to protect end-users from hidden data-sharing practices. The incident serves as a stark reminder for consumers to remain informed about the applications they install and the permissions they grant, even on seemingly simple devices like smart televisions. The underlying technology of residential proxies, while offering legitimate uses for data access, requires robust oversight and transparent implementation to prevent its abuse, particularly when embedded within consumer electronics that are not typically subject to the same level of user scrutiny as personal computers.

