New cybersecurity research found several Samsung Smart TV apps containing residential proxy software that could share users' internet connections, prompting the company to tighten developer policies and remove apps with the controversial functionality.
Samsung has announced stricter measures for applications available on its Smart TV platform after new cybersecurity research revealed that several apps contained software capable of sharing users' internet connections with external parties. The findings have raised concerns about the potential misuse of consumer devices through residential proxy technology, a mechanism that can route internet traffic through home networks.
According to research published by Norwegian cybersecurity firm Mnemonic, some Smart TV applications available through Samsung's app marketplace included residential proxy software development kits (SDKs). The researchers warned that, once activated with user consent, these components could allow a television to function as an "exit node," enabling third-party internet traffic to pass through the owner's network connection.
The report noted that several of the affected applications had significant user reach, with developers claiming installations across hundreds of millions of Smart TVs. Among the examples highlighted was a Pac-Man game that had previously appeared in Samsung's "Editor's Choice" recommendations.
Following the publication of the findings, Samsung confirmed it had begun removing applications containing residential proxy functionality and had introduced stricter requirements for developers submitting new apps to its Smart TV platform.
Samsung tightens app policies after findings
In its response, Samsung said it has already blocked new app submissions that include residential proxy capabilities and is implementing platform-wide policies prohibiting such software. The company added that it is actively identifying and removing existing applications that contain these components.
The research suggested that many Smart TV apps rely on lightweight code that primarily loads content from external web servers. As a result, security reviews may evaluate only the basic application code while overlooking content or functionality delivered remotely after installation.
According to the researchers, this architecture can make it difficult to determine exactly what software is running on a device at any given time, creating opportunities for additional functionality to be introduced without being fully visible during the review process.
Samsung's move follows a similar decision by LG Electronics, which recently announced plans to prohibit applications using residential proxy software after separate reports highlighted their presence within its Smart TV ecosystem.
Residential proxy networks under increasing scrutiny
Residential proxy networks are not inherently malicious and have legitimate commercial applications. They are commonly used to bypass geographical restrictions, conduct market research and support large-scale web data collection, including public data gathering for artificial intelligence model training.
However, cybersecurity experts caution that such networks have increasingly attracted misuse by cybercriminals seeking to disguise malicious online activity. Because internet traffic appears to originate from legitimate residential connections rather than suspicious infrastructure, identifying and blocking malicious activity becomes significantly more challenging for security teams.
During the investigation, Mnemonic researchers analysed network traffic on a rooted Samsung Smart TV and found residential proxy code linked to Bright Data within one application. The researchers observed that the proxy component remained inactive until users accepted a consent prompt, after which it could continue operating in the background until the application was removed.
The researchers also warned that software delivered remotely could potentially alter application behaviour through server-side changes, increasing the importance of stronger platform oversight and developer verification.
Bright Data later stated that it maintains strict compliance standards, conducts customer identity verification and actively monitors its proxy network to prevent abuse. The company maintained that only a small proportion of customers violate its policies, although it did not disclose specific figures.
The findings underscore growing concerns around the security of connected consumer devices and highlight the need for stronger app review mechanisms as smart home ecosystems continue to expand.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




