LG to Ban Residential Proxy SDKs from WebOS Smart TV Apps
LG Electronics has announced a crackdown on residential proxy software development kits (SDKs) embedded in apps distributed through its webOS smart TV platform. The decision follows research from security firm Spur.us, which found that more than 42 percent of apps available in the LG webOS store contained SDKs capable of transforming a user's television into an always-on residential proxy node. The same study revealed that over a quarter of apps built for Samsung's Tizen OS carried comparable components, making smart TVs a quietly growing vector for traffic anonymization services.
In a statement to KrebsOnSecurity, LG Senior Vice President John Taylor confirmed the company is actively working with developers to strip residential proxy functionality from their apps. Apps that fail to comply will be suspended from the store. "A residential proxy network is not an intended use for LG smart TVs," Taylor said. "LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform. If this option is not removed, these apps will be suspended." LG indicated that its review process is already underway and that stricter evaluation criteria for developer-submitted apps will follow, marking a notable regulatory shift by a major original equipment manufacturer against embedded SDK abuse.
Spur's report identified Bright Data as the dominant residential proxy SDK provider across both Samsung and LG platforms, bundled in everything from casual games like Pac-Man to screensavers and file utilities. In many cases, users are presented with a simple choice: watch an advertisement or allow their TV to be rented out as a proxy node — often without a clear understanding of what that entails. Residential proxy networks operate by paying developers to enroll user devices, then reselling that bandwidth and IP reputation to paying customers, frequently for web scraping, ad verification, or evading geographic restrictions. Bright Data and other providers named in Spur's report claim they follow rigorous know-your-customer (KYC) vetting processes, though critics argue the resulting traffic is regularly repurposed for less legitimate ends.
For consumers, the episode underscores how deeply privacy-compromising code can be hidden in everyday applications. Users who suspect their network or devices may already be relaying traffic through unfamiliar intermediaries can run a VPN and proxy detection scan to audit active connections, while a browser fingerprint test can reveal how identifiable their setup remains even across sessions. A broader privacy checkup is recommended for anyone who has installed third-party apps on a smart TV platform, particularly LG webOS or Samsung Tizen devices, to assess what other data their devices may be quietly exposing.