Samsung has banned hundreds of smart TV apps, here’s the big why

Samsung has banned hundreds of smart TV apps, here's the big why

Samsung has banned hundreds of smart TV apps. The company said it is removing the apps that contain residential proxy software after new cybersecurity research found some apps could allow users’ internet connections to be shared with outsiders. The findings, published by Norwegian cybersecurity firm Mnemonic, identified several apps on Samsung’s TV app store, including one previously featured in the company’s “Editor’s Choice” section, that contained software capable of turning televisions into residential proxy exit nodes after users granted consent.Responding to the findings, Samsung said it had already begun restricting such apps. “We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform,” a Samsung spokesperson said. “We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components.

Why Samsung is removing these apps

Residential proxy networks, also known as resproxies, route internet traffic through ordinary residential internet connections instead of commercial servers. While the technology has legitimate uses, including bypassing internet censorship and collecting publicly available web data, cybersecurity companies say such networks are increasingly being linked to cybercrime because they can disguise the origin of online activity.Mnemonic’s research found that several Samsung TV apps contained Bright Data’s residential proxy SDK. The SDK remained inactive by default and only became operational after users accepted a consent screen. Once enabled, the background service continued running even after the app was closed, allowing the television to function as an exit node until the app was removed.Researchers also warned that the SDK’s behaviour could be controlled remotely. Harrison Sand, offensive security consultant at Mnemonic, said a “simple code change on a web server” could activate residential proxy functionality across hundreds of millions of compatible smart TVs.

Pac-Man app among those examined

One of the apps analysed was a Pac-Man game developed by Play.Works that Samsung had previously featured in its “Editor’s Choice” section. Mnemonic found that the app included Bright Data’s SDK, although the residential proxy feature remained disabled during testing.The researchers said many Samsung TV apps are lightweight web applications that load most of their functionality from remote servers rather than from code reviewed during the app approval process. As a result, “What was reviewed is not necessarily what is running,” Sand wrote in the report.According to the researchers, this architecture makes it difficult for app store operators to verify whether applications continue to comply with platform policies after approval.

Research examined network activity

To analyse the apps, Mnemonic researchers rooted a Samsung smart TV and monitored network traffic flowing through the device. They found that traffic routed through the residential proxy network appeared to include requests related to large-scale LinkedIn profile collection, AI training datasets and public web scraping, although they said they observed only a small fraction of the overall traffic handled by Bright Data’s network.The report noted that Bright Data requires user consent before activating its SDK and has customer verification processes for organisations using its residential proxy services.Samsung’s action follows a similar decision by LG, which announced last month that it would also prohibit apps containing residential proxy software after separate research found that around 42% of apps on its smart TV app store contained similar functionality.

Leave a Comment