LG Electronics has announced it will suspend any smart TV app on its webOS platform that turns a user’s television into an always-on residential proxy node. The decision follows research from the security firm Spur, which revealed that over 42 percent of games and other apps available on LG’s webOS store contain software development kits (SDKs) that allow unknown third parties to route internet traffic through a user’s television without their ongoing awareness.
The findings, published by Spur in early July, highlighted a troubling trend in the smart TV ecosystem. Residential proxy SDKs are designed to transform a device into a proxy server, renting out the user’s IP address and bandwidth to paying customers. Spur identified these SDKs in more than a quarter of apps built for Samsung’s Tizen operating system as well, with the proxy network Bright Data accounting for the majority of the integrations across both platforms. In LG’s case, the SDKs were found bundled into a broad range of software, from simple games like Pac-Man to screensavers and file utilities.
Responding to questions about the research, LG Senior Vice President John Taylor confirmed the company is actively working with developers to remove the residential proxy option from their apps. “A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor stated. “If this option is not removed, these apps will be suspended.” Taylor added that the company’s review is well underway and that LG will continue to strengthen its evaluation process for developer-submitted apps that incorporate such SDKs.
How Smart TV Proxy SDKs Turn Appliances Into Surveillance Nodes
The core issue lies in the opaque nature of these SDKs and the consent mechanisms that enable them. App developers are paid by proxy providers to include the SDK as a monetization strategy. For the user, consent is often buried in a one-time prompt during app setup, a practice Spur’s Trevor Sutter described as inadequate. “A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight,” Sutter wrote. “The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors.”
Once a user agrees, their television becomes a conduit for internet traffic from unknown third parties. While companies like Bright Data claim to employ rigorous know-your-customer (KYC) processes and technological countermeasures to prevent clients from interacting with other devices on the proxy user’s local network, the security implications remain significant. An infected or malicious client could potentially bypass these controls, turning a home appliance into an entry point for network reconnaissance or more invasive attacks.
What Is a Residential Proxy Network and Why Is It Dangerous?
A residential proxy network is a system where internet traffic is routed through the IP addresses of real residential devices, such as computers, smartphones, and now, smart TVs. This makes the traffic appear to originate from a legitimate home user rather than a data center, allowing customers to evade geographic restrictions, scrape website content, or conduct fraud. The danger for the device owner is that this process occurs without their explicit, informed, and ongoing consent. Because the television is always on and connected to the network, it can function as a persistent proxy node, consuming bandwidth and exposing the home network to potential misuse without the owner’s knowledge.
LG’s Response and Broader Security Concerns
LG’s decision to ban these SDKs is a welcome step toward platform security, but it comes amid broader criticism of the company’s privacy practices. Earlier this week, the YouTube channel Gamers Nexus demonstrated that certain LG LCD monitors automatically install an app promoting paid McAfee antivirus subscriptions via Windows Update, without any approval prompt from the user. This pattern of embedding monetization features deep into device firmware raises questions about the company’s overall commitment to user control.
For affected users, the immediate risk is not an active exploit but a persistent loss of privacy and network integrity. The more devices in a home that act as proxy nodes, the greater the chance that an unscrupulous third party could observe or manipulate traffic, or that the home IP address could be blacklisted for abuse originating from the proxy service.
What Affected Users Should Do Now
If you own an LG smart TV, the first step is to review the apps you have installed. Look for apps that requested permission to act as a proxy or that presented confusing consent prompts about network usage. Remove any apps that you do not fully trust, especially those that are simple games or utilities that might be repurposed for proxy services. Moving forward, you should adopt a security-first approach to your home network. Use a reputable, paid VPN with a verified no-logs policy and a kill switch on any device that accesses sensitive accounts, such as laptops and phones. For the smart TV itself, consider disabling its internet connection if you primarily use an external streaming device, as those devices often have more controlled app ecosystems. Finally, enable multi-factor authentication on all your important online accounts and monitor your network traffic for unusual activity, such as unexplained high bandwidth usage from the TV. While LG’s enforcement action is pending, the most effective defense is to audit your device’s software and restrict its network permissions.