Security researchers have recently uncovered a troubling trend within the realm of Smart TV applications, particularly those associated with Samsung. Investigations revealed that several popular titles, including the well-known game Pac-Man, were secretly embedding residential proxy SDKs sourced from data brokers like Bright Data. This revelation has prompted Samsung to take decisive action against these practices.
Samsung’s Response to Proxy SDKs
In light of these findings, Samsung has announced a ban on the inclusion of residential proxy functionality in new Smart TV app submissions. The company is also actively working to purge existing applications that contain such software from its platform. This initiative aligns with a broader industry movement, as LG recently implemented similar measures after research indicated that over 42% of its webOS apps were sharing home bandwidth without user consent.
The investigation, conducted by Norwegian cybersecurity firm Mnemonic, involved rooting a Samsung Smart TV to explore the presence of residential proxy SDKs on consumer devices. Their findings revealed that the Bright Data SDK was integrated into various gaming applications, including some that had been highlighted in Samsung’s own promotional materials.
Residential proxies, while having legitimate applications such as web data collection and bypassing internet restrictions, have also gained notoriety among cybercriminals. These services route internet traffic through ordinary home connections, allowing malicious actors to obscure their activities behind residential IP addresses. The growing prevalence of this technology in consumer apps has raised significant concerns among security experts.
Fortunately, the researchers clarified that Samsung TVs were not automatically sharing their owners’ internet connections. The Bright Data SDK remained inactive unless activated remotely by the app developer, at which point users would receive a consent prompt. However, once consent was granted, the proxy service could continue to operate in the background, even after the application was closed.
Another alarming aspect of this situation is the architecture of many Samsung TV applications. Mnemonic discovered that numerous apps function as lightweight shells, downloading most of their code from remote servers. While this approach allows developers to push updates without the need for app review, it creates a significant blind spot. Features can change post-approval, complicating the verification process for Samsung and other app store operators regarding what users are actually running on their devices.
This issue extends beyond Samsung, as the presence of residential proxy software has been identified in various Android apps, Android TV streaming devices, and even digital picture frames. Such widespread adoption highlights the urgent need for industry-wide vigilance against these practices.
Samsung’s recent policy shift reflects a growing recognition of the risks associated with residential proxy networks. Following LG’s announcement, Google has also taken steps to address this issue by disrupting the NetNut residential proxy network and enhancing Google Play Protect to alert users about apps containing the NetNut SDK. With millions of devices, including smart TVs and streaming boxes, potentially enrolled in these networks, the industry’s response is becoming increasingly critical.