2 min read

LG Will Suspend Smart TV Apps Using Proxy SDKs

LG says it will suspend webOS apps that turn smart TVs into residential proxy nodes after research found the code in 42% of store apps.

Image: Krebs on Security

LG Electronics USA says it will suspend smart TV apps on webOS if developers do not remove software that turns a television into an always-on residential proxy node. The move follows research published on July 2 by security firm Spur, which found that more than 42 percent of apps available for download on LG smart TVs include proxy SDKs. Spur also found that more than a quarter of apps built for Samsung’s Tizen operating system contain similar components.

Responding to questions from KrebsOnSecurity, LG Senior Vice President John Taylor said the company is working with developers to remove the feature and will suspend apps that fail to comply.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform. If this option is not removed, these apps will be suspended.”

John Taylor, Senior Vice President, LG

Taylor added that LG’s review of affected apps is “well underway now” and said the company plans to strengthen its vetting process for developer-submitted apps, including those that use residential proxy SDKs.

Residential proxy providers pay app developers to bundle SDKs that let the user’s device be rented out to paying customers as a proxy endpoint. According to Spur, those SDKs showed up in LG and Samsung TV apps ranging from Pac-Man to screensavers and file utilities.

Recommended reading

OpenAI says rogue models hit Hugging Face

A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node. Image: Spur.us.
A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node. Image: Spur.us.

Spur said Bright Data accounted for a majority of the proxy SDKs found across both LG and Samsung smart TVs. Bright Data did not respond to requests for comment. The proxy companies named in Spur’s report say they use know-your-customer checks and technical controls designed to stop customers from interacting with other devices on a proxy user’s local network.

Spur’s Trevor Sutter argued the larger issue is how widely these SDKs are being embedded in devices that consumers do not usually treat as general-purpose computers.

“A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight. The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors.”

Trevor Sutter, Spur

LG’s crackdown comes as the company also faces criticism over another software bundling issue. Earlier this week, the YouTube channel Gamers Nexus reported that certain LG LCD monitors automatically install an app promoting paid McAfee antivirus subscriptions through Windows Update, without an approval prompt.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via Krebs on Security

// Keep reading