Particle.news

Samsung Bans Smart TV Apps That Route Stranger Traffic Through Users' Networks

The move follows Mnemonic's technical report showing some apps can turn TVs into always‑on exit nodes that hide third‑party activity behind residential IP addresses.

Overview

  • Samsung said on Monday it has restricted new app registrations with proxy functionality and will implement platform rules to ban residential proxy SDKs and remove apps that contain them.
  • Norwegian security firm Mnemonic rooted a Samsung TV and found resproxy code in a featured Pac‑Man app that activates after a consent prompt and continues running in the background until the app is deleted.
  • Residential proxies let outsiders route web requests through ordinary home IP addresses and are used for tasks like large‑scale web scraping or censorship circumvention but are also attractive to attackers because the traffic looks like normal household activity and is usually encrypted.
  • Researchers warn the problem is hard to spot because many smart TV apps are thin shells that load code from remote servers, allowing proxy behavior to be introduced or switched on after app review and to scale rapidly across devices.
  • Samsung is scanning and removing affected apps while LG has taken similar steps, and investigators say the full scale, any dormant code and the potential for remote activation remain open questions for users and platform security teams.