LG Takes Action Against "Proxy-Enabled" Smart TVs Following Security Revelations
In a significant move to reclaim control over its digital ecosystem, LG Electronics USA announced this week that it will begin suspending smart TV applications that utilize residential proxy software development kits (SDKs). The decision follows a blistering report from security firm Spur, which exposed a pervasive trend: a massive portion of the apps available on LG’s webOS platform were covertly transforming household televisions into "always-on" residential proxy nodes without the consumer’s full awareness of the long-term implications.
This policy shift marks a turning point for manufacturers who have long struggled to balance the monetization desires of app developers with the privacy and security expectations of their customers. As smart devices become the center of the modern home, the discovery that nearly half of an app store’s catalog could be repurposing home bandwidth has sent shockwaves through the consumer electronics industry.
The Anatomy of the Proxy Problem: How Your TV Became a Node
To understand the scope of the issue, one must first understand what a "residential proxy" actually does. In simple terms, these SDKs allow a third party to route their internet traffic through a user’s home IP address. By doing so, the third party can make their activities—which often involve data scraping, market research, or bypassing geo-blocking—appear as though they are originating from a legitimate, residential broadband connection rather than a data center.
For the proxy provider, the value is clear: they gain access to a massive, distributed network of residential IP addresses. For the app developer, the incentive is financial; they receive payments from proxy providers for every device they "convert" into a node. However, for the consumer, the trade-off is often obscured behind a wall of "legalese" in a Terms of Service agreement that most users ignore.
The Findings: A Scale of Pervasiveness
The research conducted by Spur revealed that this practice was not an isolated incident but a structural trend. According to their data, over 42 percent of apps available for download on LG’s webOS store contained these proxy-enabling SDKs. The situation is similarly concerning for Samsung’s Tizen operating system, where over 25 percent of apps were found to harbor similar components.
These apps were not limited to obscure or suspicious software; they ranged from simple, seemingly benign tools like file managers and screensavers to popular casual games like Pac-Man. In one notable example highlighted by the researchers, a Pac-Man app offered users a "choice": watch advertisements during gameplay or agree to allow their television to serve as a residential proxy node, effectively selling the user’s home bandwidth to subsidize the game’s revenue.
Chronology: From Discovery to Policy Enforcement
The timeline leading to LG’s intervention highlights the rapid escalation of the issue following the public disclosure of the Spur report.
- July 2, 2026: Security firm Spur publishes a comprehensive analysis of the residential proxy market within the smart TV ecosystem. The report correlates the presence of these SDKs with major proxy networks, specifically identifying Bright Data as a primary supplier.
- Early July 2026: Following the report’s release, media outlets, including KrebsOnSecurity, begin questioning major TV manufacturers regarding their oversight of the third-party app stores they host.
- Mid-July 2026: LG Electronics USA acknowledges the findings and begins an internal review of the webOS app library to identify applications violating the company’s new, stricter stance on proxy usage.
- Late July 2026: LG officially declares that residential proxy networks are "not an intended use" for their hardware and announces that non-compliant apps will face suspension.
Official Responses and Corporate Strategy
The public response from LG has been decisive. John Taylor, Senior Vice President of LG Electronics USA, provided a clear mandate to developers: the practice must end, or the apps will be removed from the store.
"A residential proxy network is not an intended use for LG smart TVs," Taylor stated in an email to KrebsOnSecurity. "LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform. If this option is not removed, these apps will be suspended."

Taylor emphasized that the company’s review process is currently "well underway." Beyond simply removing the offending apps, LG is promising a structural shift in how it vets future submissions. By strengthening the evaluation process for developer-submitted apps, the company aims to prevent the resurgence of these proxy-enabled utilities.
In contrast, the proxy providers themselves have been notably quiet or defensive. Bright Data, the provider identified by Spur as the most prevalent in these ecosystems, did not respond to requests for comment. Most firms in this sector maintain that they adhere to strict "Know Your Customer" (KYC) protocols, arguing that their services are used for legitimate business intelligence and web scraping. They also claim to implement technical safeguards to ensure that proxy users cannot interact with or compromise other devices residing on the host’s local network.
Implications: The Risks of "Smart" Infrastructure
While proxy providers argue that their systems are secure, experts remain skeptical. The primary concern is not just the bandwidth usage, but the erosion of the "walled garden" security model that consumers expect from their home appliances.
The Transparency Gap
Trevor Sutter, a researcher at Spur, argues that the problem lies in the inherent lack of transparency. "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight," Sutter wrote. The risks are magnified when one considers that smart TVs are communal devices. A parent might consent to a prompt without realizing that their child, or a guest in the home, is now effectively providing a proxy service to an unknown entity for the duration of the app’s use.
The "Computer" Misconception
Consumers rarely view their televisions as computers, yet modern smart TVs have more processing power and network connectivity than the average desktop PC from a decade ago. Because they aren’t viewed as computers, they are rarely audited for security. They lack the robust firewalls, antivirus software, and behavioral monitoring tools that users typically deploy on their laptops or smartphones. This makes them the perfect "silent" hosts for proxy traffic.
Broader Trust Issues
LG’s move, while positive for consumer privacy, comes at a time when the company’s reputation for "clean" software is under scrutiny. Concurrent with the proxy controversy, LG has faced backlash for its handling of software distribution on its professional monitors. Reports from the tech channel Gamers Nexus revealed that certain LG LCD monitors were automatically installing promotional software for McAfee antivirus subscriptions via Windows Update without explicit user permission.
The convergence of these two events—the unauthorized use of home bandwidth and the unsolicited installation of promotional bloatware—suggests that manufacturers are struggling to manage the complex, multi-party software ecosystems that define modern consumer hardware.
Moving Forward: What Consumers Should Do
As the industry grapples with these revelations, the onus currently falls on the consumer to remain vigilant. While LG’s intervention will clean up the webOS store, the reality is that the "Smart TV" landscape remains a patchwork of operating systems, many of which may not yet have the same stringent policies as the updated LG standards.
- Monitor Network Traffic: Advanced users may want to monitor their router logs to see if their smart TVs are communicating with known proxy infrastructure providers.
- Audit App Permissions: Periodically check the "Manage Apps" or "Settings" menu on your smart TV. If an app seems to be requesting excessive network permissions or has a "privacy policy" that mentions "data sharing" or "proxy services," it is safer to uninstall it.
- Restrict Unnecessary Access: If your TV supports it, disable automatic updates or "promotional" notifications if you find that the manufacturer is using them to push third-party software like the McAfee issue noted earlier.
Ultimately, LG’s decision to ban residential proxy SDKs is a victory for consumer autonomy. It reinforces the principle that a device purchased for the home should be a tool for the user, not a platform for third-party commercial exploitation. Whether other manufacturers follow suit—and how strictly they enforce these rules—will determine whether this was a fleeting PR move or a permanent change in the security culture of the Internet of Things (IoT).
