LG Electronics to Purge Residential Proxy SDKs from Smart TV Ecosystem Amid Security Concerns
In a significant policy shift, home appliance giant LG Electronics USA has announced it will begin removing applications from its webOS platform that utilize residential proxy software development kits (SDKs). The move comes in the wake of an alarming investigation by security research firm Spur, which revealed that a substantial portion of the apps available on LG’s smart TVs were secretly—or via obscure consent—turning users’ living room televisions into always-on residential proxy nodes.
This crackdown, which LG confirms is already underway, marks a turning point in the ongoing struggle between device manufacturers, software developers seeking new revenue streams, and security advocates who argue that smart home devices have become the "low-hanging fruit" of the internet-of-things (IoT) security landscape.
The Discovery: Your TV as a Proxy Server
The controversy began in early July 2026, when security firm Spur published a comprehensive report detailing the prevalence of residential proxy SDKs within the smart TV ecosystem. The research found that over 42 percent of apps available on LG’s webOS store contained code that effectively transforms a television into a proxy node. This functionality allows third parties to route their internet traffic through the user’s home network, effectively masking the true origin of their web activities.
The problem is not limited to LG. Spur’s data indicated that more than a quarter of the applications developed for Samsung’s Tizen operating system also harbor these proxy components. From simple puzzle games like Pac-Man to utility apps and screensavers, the scope of the integration suggests that developers have increasingly viewed the idle bandwidth of smart TVs as a monetizable commodity.
Chronology of the Crisis
- Early July 2026: Researchers at Spur identify a widespread trend of residential proxy SDKs being embedded in consumer smart TV applications.
- July 2, 2026: KrebsOnSecurity highlights the research, bringing the issue to mainstream attention and linking it to broader concerns regarding the misuse of residential IP addresses for botnet-like activities.
- Mid-July 2026: LG Electronics comes under pressure to address the findings, as privacy advocates and security researchers question the legitimacy of "consent" obtained via buried, one-time prompts in non-essential applications.
- July 22, 2026: LG officially confirms to stakeholders that it is actively working to remove these SDKs from the webOS platform. The company warns that any developer failing to strip this functionality will face immediate suspension of their applications from the storefront.
- Late July 2026: Concurrent with the proxy controversy, reports emerge regarding LG’s questionable bundling of third-party antivirus software via Windows Update, further complicating the company’s reputation regarding user control and software transparency.
The Anatomy of the Monetization Model
To understand why developers are embedding these SDKs, one must look at the lucrative nature of residential proxy networks. Proxy providers pay app developers a fee to include their SDKs. Once the app is installed and the user grants permission—often buried in lengthy, dense "Terms of Service" agreements—the TV joins a network of residential IPs.
These networks are highly valued by commercial entities and data-scraping firms. Because the traffic originates from a residential IP address rather than a known data center, it is much harder for websites to block or flag as suspicious. While providers like Bright Data argue that their services are used for legitimate research and market analysis, the potential for abuse—including credential stuffing, ad fraud, and accessing geo-restricted content—is high.
Bright Data, which was identified as a primary provider of these SDKs in the Spur report, issued a statement defending its business model. "Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC," the company stated. They emphasize that they implement strict "know-your-customer" (KYC) protocols to ensure the network is not misused for malicious activities.
Official Responses and Corporate Strategy
LG Senior Vice President John Taylor provided a definitive stance on the matter, signaling a clear departure from the company’s previous hands-off approach to third-party app development.

"A residential proxy network is not an intended use for LG smart TVs," Taylor stated in an email. "LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform. If this option is not removed, these apps will be suspended."
Taylor further noted that the company is currently engaged in a comprehensive review of its entire app catalog. Moving forward, LG plans to implement a more rigorous evaluation process for developer-submitted applications to ensure that no future software can sneak such invasive telemetry or proxy functionality into the user’s home environment without explicit, transparent, and ongoing oversight.
The Security Implications: Why This Matters
The primary argument against this practice, as articulated by Trevor Sutter of Spur, is the lack of "meaningful transparency." Smart TVs are not treated as computers by the average consumer. They are viewed as appliances, and users rarely consider that their television possesses the processing power and network connectivity to act as a server for third-party traffic.
1. Informed Consent and Vulnerable Users
The issue of consent is paramount. A one-time prompt shown to an adult user may not be understood by other members of the household, including minors or elderly family members. When a device is effectively "hijacked" for a proxy network, the primary user may not even realize that their internet bandwidth is being consumed, or worse, that their network might be associated with illicit traffic originating from a third party.
2. Local Network Risks
While proxy providers claim to use technological countermeasures to prevent "cross-talk"—where a proxy user might attempt to scan or interact with other devices on the TV owner’s local network—security researchers remain skeptical. The fundamental architecture of a proxy node inherently creates a bridge between an untrusted external party and the internal home network. For a device that sits on the same network as private PCs, smartphones, and IoT security cameras, this represents an unnecessary and unacceptable attack surface.
3. The "Platform Quality" Dilemma
LG’s recent challenges extend beyond proxy SDKs. The revelation that certain LG monitors have been automatically installing McAfee antivirus software via Windows Update—without explicit user prompt—has exacerbated concerns regarding the company’s respect for user agency. Critics argue that LG is prioritizing short-term revenue partnerships over the long-term integrity of its product ecosystem.
Implications for the Future of IoT
The LG incident serves as a wake-up call for the broader IoT industry. As the line between "appliance" and "computer" continues to blur, the standards for software transparency must rise.
- For Developers: The era of "monetization at any cost" is facing a regulatory and platform-level reckoning. Developers must be prepared for stricter auditing and potential bans if they rely on invasive background processes.
- For Manufacturers: LG’s commitment to cleaning up its webOS platform sets a new industry standard. Competitors like Samsung and Vizio will likely face increased pressure to perform similar audits of their own app stores.
- For Consumers: This serves as a reminder that "smart" devices are essentially computers. Users should be increasingly wary of the permissions requested by simple utility apps and should look for ways to monitor network traffic from their home devices using tools like firewalls or network-level logging.
As LG continues its review process, the industry will be watching to see how many apps are ultimately purged and whether this action will be enough to restore consumer trust. For now, the "always-on" proxy node, once a hidden feature of the smart TV experience, is being pushed back into the shadows—exactly where it belongs.
