Samsung moves to remove smart TV apps containing residential proxy code

Samsung is banning smart TV apps that share owners’ internet connections through residential proxy networks and says it will remove existing apps containing the functionality. The decision follows research by Norwegian cybersecurity company Mnemonic, which found proxy code in popular apps, including a Pac-Man game that Samsung had featured in its Editor’s Choice section.
Some developers claim their apps have been installed on hundreds of millions of smart TVs. Residential proxy software can route a paying outsider’s traffic through a home or office connection, potentially leaving the television operating as an always-on tunnel even after the app itself has been closed.
Why app review can miss remote behaviour
Mnemonic described many Samsung TV apps as bare-bones shells comprising only a few lines of code. Rather than carrying their full content locally, they load a game or other material from a remote website. That design means an app review may inspect the shell without necessarily seeing the content subsequently delivered by the server.
“What was reviewed is not necessarily what is running,” wrote Harrison Sand, an offensive security consultant at Mnemonic.
After being contacted about the findings, Samsung said it had already restricted new app registrations incorporating proxy functionality. The company is implementing platform-wide developer policies that explicitly ban residential proxy SDKs and is working to identify and remove affected apps from its store.
The action follows LG’s decision to prohibit comparable software after reporting found that about 42% of apps in its store enrolled a smart TV into a proxy network.
What Mnemonic found inside the television
Sand rooted a Samsung smart TV to inspect its internal operation and network traffic. He found that the featured Pac-Man game contained residential proxy code supplied by Bright Data, an Israel-based provider that advertises access to millions of residential networks and operates a marketplace for scraped datasets.
The findings add enforcement context to Bright Data smart TV proxy operations, showing how consent and remote content can determine whether embedded proxy software becomes active. In Sand’s test, the Bright Data component loaded when the game opened but did not immediately make the television an exit node.
The code remained dormant until the user accepted a consent screen. Acceptance activated it in the background, where it continued running until the app was deleted. Sand also warned that a simple change on a web server could activate vast numbers of installed televisions without changing the small app shell reviewed by the store.
Why residential proxies create security concerns
Residential proxies are not inherently illegal. They can help users evade censorship, and AI companies use them to collect public web data from multiple locations. Similar code also appears in phone apps, digital frames and Android streaming boxes.
However, cybersecurity companies associate these networks with attackers and spies who want their activity to appear as traffic from an ordinary household. The traffic routed through a device is generally encrypted, making it difficult for defenders to inspect. In Sand’s limited view of Bright Data traffic, much of the activity appeared related to large-scale LinkedIn profile scraping and AI training data collection. Bright Data did not respond to a request for comment.
Business implications
Organizations should treat smart TVs as managed network devices rather than passive displays. A practical response is to inventory installed apps, remove software that is unnecessary, scrutinize consent prompts, and isolate televisions from sensitive systems where network design permits. Samsung’s policy change reduces future exposure, but identifying and deleting existing proxy-enabled apps remains important.

