New security research published on Monday reveals that several popular Samsung smart TV apps contain code sharing owner internet connections with strangers. This potentially puts millions of Samsung smart TVs at risk of hijacking. App developers claim some of these programs were installed on hundreds of millions of home televisions. One such app was a simple Pac-Man game prominently featured in Samsung Editor Choice section.
These applications contain software routing outsider web traffic through ordinary home and office connections. Known as residential proxy networks or resproxies, these systems face increasing links to cybercrime. Opened apps with this code can turn smart televisions into always-on tunnels for outside traffic to flow through, acting as exit nodes even after closing the app. Norwegian cybersecurity firm Mnemonic conducted the research and described a problem allowing low-quality apps to proliferate across the app store.
Many apps are barebone shells made from few lines of code designed solely to load external web content. Harrison Sand, an offensive security consultant at Mnemonic, noted that reviewed code differs from running code. TechCrunch contacted Samsung for comment, and the company stated it will ban apps sharing user connections and remove existing ones with this functionality. A Samsung spokesperson confirmed new app registrations incorporating proxy features are restricted. The company is implementing strict developer policies and working to remove store apps containing these components.
LG announced a similar ban last month after reports showed about 42% of apps on its store enlisted smart TVs into proxy networks. Residential proxy code also appears in consumer phone apps, digital frames, and Android streaming boxes. Resproxies are not inherently illegal and help evade censorship or assist AI companies in scraping web data for training models. However, cybersecurity firms note these networks allow hackers and spies to hide malicious activity during attacks and data breaches.
Security analysts find resproxies challenging because traffic mimics ordinary household usage rather than overseas hackers. The traffic is also encrypted and impossible to inspect. Sand gained deep internal access to a Samsung television by rooting its software to analyze network traffic. He discovered the Pac-Man game contained resproxy code from Bright Data, an Israel-based company providing proxy networks and data scraping marketplaces.
Sand found the Bright Data code loaded when opening the Pac-Man game and activated after users accepted a consent screen. The code then runs in the background until the user deletes the app. Sand warned that a simple code change on a web server could instantly activate hundreds of millions of televisions into a botnet. Network data indicated the proxy network was used for scraping LinkedIn profiles and collecting AI training data.
Samsung is currently implementing strict platform-wide developer policies explicitly banning residential proxy software development kits. The electronics giant is working to identify and remove all apps currently available in its store that contain these components.



