Multiple widely used Samsung smart TV apps include code that routes the owner's internet connection to strangers, potentially exposing millions of Samsung smart TVs to exploitation, according to new security research released Monday by Norwegian cybersecurity firm Mnemonic. Some of these apps claim installation on hundreds of millions of smart TVs in homes worldwide, based on figures from the app developers. At least one app—a basic Pac-Man game—had earned Samsung's endorsement and appeared prominently in the company's "Editor's Choice" section on customer TV screens.

The apps contain software that channels outsiders' web traffic through regular home and office internet connections, known as residential proxy networks or "resproxies," which are increasingly connected to cybercrime. When launched, apps carrying resproxy code can transform the smart TV into a permanent tunnel for outsiders to route their web traffic through, called an exit node—even after the app has been closed. Harrison Sand, an offensive security consultant at Mnemonic, described a perfect storm of issues that lets low-quality apps spread across Samsung's app store with code that risks users' internet connections being tapped by a rogue app. Many of these apps are skeletal shells built from just a few lines of code, created solely to pull content from another website, like a game. While such smart TV apps load content from another server, any review of these apps examines only the few lines of code inside, not necessarily the content itself. "What was reviewed is not necessarily what is running," Sand wrote.

After being contacted by TechCrunch about the research, Samsung announced it would ban apps that share users' internet connections and remove apps with this capability. "We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform," a Samsung spokesperson said. The company is rolling out strict platform-wide developer policies explicitly prohibiting residential proxy SDKs and working to identify and eliminate all apps currently in its store containing these components. The decision follows LG's announcement last month that it would ban apps with resproxy software after recent reporting discovered that roughly 42% of apps on the company's app store enrolled a smart TV into a proxy network.

The research offers a rare glimpse inside a residential proxy network. Resproxy code also appears in regular consumer phone apps and other electronics, like digital frames and Android streaming boxes, which then share that device's internet connection. Whenever a resproxy app or device connects to the internet, an outsider can pay to use it. While resproxies aren't inherently illegal—some are used for evading censorship by routing internet traffic through ordinary-looking residential homes, and AI companies increasingly rely on them to scrape data from multiple internet sources at once to train AI models—cybersecurity firms say resproxies have earned a reputation for enabling hackers and spies to conduct cyberattacks and data breaches while concealing their malicious activity. Cybersecurity companies find resproxies difficult to combat because the network traffic appears to originate from an ordinary household rather than a malicious hacker overseas. The network traffic flowing through a user's device over resproxies is generally encrypted, making it essentially impossible to decode and examine.

By rooting a Samsung smart TV's software, Sand gained deep access to the television's internals and analyzed all network traffic flowing in and out of the TV, including any app sharing the smart TV's internet connection with someone else. He discovered the Pac-Man game contained resproxy code from Bright Data, an Israel-based company providing proxy networks claiming access to millions of residential networks globally. The company also operates a marketplace for selling access to scraped datasets derived from a network of enlisted smart TVs as exit nodes, used to download large volumes of public data from the web from multiple sources simultaneously, often to bypass systems designed to prevent scraping. Sand found that Bright Data's resproxy code loaded when opening the Pac-Man game but noted this didn't automatically convert the Samsung smart TV into an exit node. The resproxy code stays dormant until the user accepts a consent screen, which immediately activates the resproxy code to run in the background until the user deletes the app. Beyond the user consenting to enlist their device into a resproxy, Sand warned that a "simple code change on a web server" could instantly activate hundreds of millions of smart TVs into a potentially malicious botnet.

With access to network data flowing through his smart TV, Sand observed that much of it appeared to indicate the resproxy network was being used for large-scale scraping of LinkedIn profiles and for gathering AI training data. Sand noted he saw only a tiny fraction of what was routed over Bright Data's network. Samsung's move to ban these apps addresses a vulnerability that could have turned millions of living room televisions into unwitting accomplices in data scraping operations and potentially more serious cybercrimes, with users having little visibility into how their internet connections were being exploited.