Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2066+ Articles
153+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps
NEWS

LG to Ban Residential Proxies from Smart TV Apps

LG Electronics USA announced it will suspend Smart TV apps that enroll viewers' televisions into residential proxy networks — a move triggered by research revealing that more than 42% of webOS games and apps were silently turning LG TVs into always-on proxy nodes without user knowledge or consent.

Dylan H.

News Desk

July 26, 2026
6 min read

Your TV Was Probably a Proxy Node

A new report has revealed that LG Electronics USA is planning to ban and suspend any Smart TV applications built for its webOS platform that secretly enroll users' televisions into residential proxy networks. The decision follows research findings that more than 42% of games and other apps available for LG Smart TVs were silently operating as proxy relay nodes — routing third-party internet traffic through living rooms worldwide.

The story was first reported by KrebsOnSecurity, which investigated the widespread abuse of webOS's permissive app ecosystem to embed proxy SDK code into otherwise legitimate applications.


What Is a Residential Proxy?

A residential proxy is an internet relay node that routes traffic through a real consumer IP address — making the traffic appear to originate from a legitimate home user rather than a datacenter. Residential proxies are commercially valuable because they bypass IP-based blocking and rate limiting:

Use CaseLegitimacy
Web scraping at scaleGrey area / often ToS violation
Ad fraud and click fraudIllegal
Bypassing geo-restrictionsGrey area
Credential stuffing attacksIllegal
Sneaker bot purchasingToS violation
CAPTCHA bypass operationsToS violation

Residential proxy networks charge a premium for IP addresses tied to real consumer devices. A Smart TV with a persistent internet connection is an ideal candidate — always online, rarely monitored, and operating under a clean residential ISP IP address.


Scale of the Problem

MetricFinding
Apps embedding proxy SDKs42%+ of webOS app catalog
Category most affectedGames and entertainment apps
User consent providedNone in identified cases
Disclosure in privacy policyTypically absent or buried
LG's responseSuspend offending apps

The apps were not standalone malware — they were functional games and utilities that had integrated third-party SDKs from residential proxy companies. Developers were compensated for embedding these SDKs, often framing the arrangement as "bandwidth sharing" or "unused resource monetization."


How the SDKs Work

1. User downloads and installs a legitimate-looking webOS app (e.g., a game)
2. App bundles a residential proxy SDK (e.g., from an SDK provider)
3. On launch, SDK registers the TV's IP with the proxy provider's infrastructure
4. TV silently routes external traffic through its connection in the background
5. Third parties pay the proxy provider for access to "residential IPs"
6. Developer receives revenue share; user has no visibility or consent

The traffic routed through the TV can include web scraping requests, ad verification probes, credential stuffing attacks, or other activity originating from unknown third parties — all appearing to come from the homeowner's internet connection.


LG's Response

LG Electronics USA has stated it will suspend apps that violate its developer policies by enrolling TVs into proxy networks. The company indicated this action is being taken to:

  1. Protect users from unauthorized use of their network connections
  2. Enforce existing developer guidelines around background network activity
  3. Respond to the documented research findings

LG has not yet published a comprehensive list of suspended apps or a timeline for enforcement. The company is reportedly auditing its webOS app catalog for proxy SDK integrations.


Why This Matters Beyond LG

The issue is not unique to LG's webOS platform. Smart TVs from multiple manufacturers — running Android TV, Tizen (Samsung), VIDAA (Hisense), and Roku OS — have faced similar concerns. The characteristics that make Smart TVs attractive as proxy nodes apply across the industry:

FactorRisk
Always-on connectionPersistent availability as a proxy node
Residential ISP IPBypasses datacenter IP blacklists
Minimal user monitoringLow detection likelihood
Permissive app ecosystemsSDK embedding is easy to accomplish
Long device lifecycles5-10 year lifespan means persistent exposure

What You Can Do

Check Your TV's Network Activity

# On your router, check for unusual outbound connections from your TV's IP
# (commands vary by router firmware)
# Look for persistent connections to unfamiliar IPs on your TV's MAC address
 
# On pfSense / OPNsense: Diagnostics > States > filter by TV IP
# On Ubiquiti: Clients > TV device > Traffic stats

Restrict Smart TV Internet Access

Many security-conscious users segment Smart TVs onto a guest VLAN or IoT network with restricted outbound access:

Recommended firewall rules for Smart TV VLAN:
  Allow: streaming service IPs (Netflix, Disney+, YouTube CDNs)
  Allow: NTP (time sync)
  Block: all other outbound traffic by default
  Alert: on unusual outbound volume or connection count

Audit and Remove Suspicious Apps

  1. Navigate to your LG TV's app manager
  2. Review all installed apps — especially games from unknown developers
  3. Remove any apps you do not actively use
  4. Factory reset if you suspect extensive proxy SDK embedding

Enable DNS-Based Filtering

Use a Pi-hole, AdGuard Home, or NextDNS resolver on your network to block known proxy SDK domains and C2 infrastructure.


Broader IoT Security Implications

This incident highlights a persistent challenge in the IoT security landscape: consumer devices are increasingly capable computing nodes, but users have limited visibility into what runs on them.

The residential proxy SDK problem is a softer version of the same threat model as traditional IoT botnets — the device is conscripted into a network for third-party benefit without the owner's knowledge. The difference is that proxy SDK operators operate commercially and (arguably) legally in grey-market territory, making enforcement complex.

Regulators in the EU under GDPR and in California under CCPA have grounds to challenge proxy SDK deployments as unauthorized processing of network resources — but enforcement against embedded SDKs in consumer electronics remains largely untested territory.


Sources

  • KrebsOnSecurity — LG to Ban Residential Proxies from Smart TV Apps
  • LG Electronics Developer Policy

Related Reading

  • DOJ Disrupts 3 Million Device IoT Botnets Behind Record 314 Tbps Global DDoS Attack
  • Shadow AI Risk: How SaaS Apps Are Quietly Enabling Massive Breaches
#LG#Smart TV#Residential Proxies#IoT Security#Privacy#webOS

Related Articles

Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI

A researcher has reverse-engineered the iOS SDK that Bright Data embeds in consumer apps and documented how it turns devices — including always-on smart TVs…

8 min read

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

Researchers at Guardio disclosed a now-patched vulnerability chain in the Adobe Acrobat Chrome extension dubbed HermeticReader, which could allow...

4 min read

Spain Fines 23andMe Nearly $3 Million for Cybersecurity Failings Enabling 2023 Hack

Spain's data protection agency AEPD has fined 23andMe approximately $3 million for cybersecurity failures that enabled the 2023 credential-stuffing breach...

5 min read
Back to all News