Samsung bans TV apps sharing your Wi-Fi with strangers – Claril Noticias

Samsung has banned smart TV apps worldwide this Monday after cybersecurity researchers discovered that several popular applications, including an officially endorsed Pac-Man game, were secretly sharing users’ home internet connections with third parties, exposing millions of devices to potential cyber hijacking.

According to the application developers, some of these compromised programmes claim to have been installed on hundreds of millions of smart TVs globally.

Alarmingly, at least one affected application was a basic Pac-Man game that Samsung had not only approved but also actively promoted within the “Editor’s Choice” section on its customers’ television screens.

How rogue apps hijack your smart TV

These applications contain hidden code designed to route external web traffic through standard home and office internet connections. This mechanism, known as a residential proxy network (or “resproxy”), is increasingly being exploited for cybercrime. Once launched, an app embedded with resproxy code can transform a smart TV into a permanent “exit node” for external users, continuing to funnel third-party traffic even after the application has been closed.

The loophole in Samsung’s app review process

A security research report published by the Norwegian cybersecurity firm Mnemonic highlights a systemic vulnerability in Samsung’s ecosystem. This flaw allows low-quality, malicious applications to proliferate across the official app store, exposing users to the risk of having their private networks intercepted.

Many of these applications operate as bare-bone shells consisting of only a few lines of code. Their sole purpose is to load external web content, such as a hosted game. Because the app store vetting process only reviews the static code submitted within the package and not the dynamically loaded external content, the malicious behaviour easily bypasses detection.

“What was reviewed is not necessarily what is running,” explained Harrison Sand, an offensive security consultant at Mnemonic.

Samsung and LG crack down on residential proxies

Following inquiries from journalists regarding the security findings, the South Korean electronics giant confirmed it is banning all applications that share user internet connections and is actively purging them from its platform.

“We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform,” a Samsung spokesperson stated. “We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components.”

This decisive action follows a similar move by rival manufacturer LG, which recently announced it would ban apps that contain resproxy software. Investigations revealed that approximately 42% of the applications hosted on LG’s app store were covertly enrolling smart TVs into proxy networks.

The dark side of residential proxy networks

The investigation provides a rare, detailed look into the inner workings of residential proxy networks.

Resproxy code is not exclusive to smart TVs; it is frequently embedded within standard mobile applications, digital photo frames, and Android streaming boxes, silently sharing the host device’s bandwidth.

Whenever a device running resproxy software connects to the internet, external entities can purchase access to use that specific connection.

While residential proxies are not inherently illegal—often used to bypass regional censorship or by artificial intelligence companies to scrape web data for model training—they present severe security challenges.

Industry experts say that these networks have gained a reputation as a preferred tool for hackers and state-sponsored spies. It allows malicious actors to execute cyberattacks and orchestrate massive data breaches whilst masking their true geographical location.

Detecting this malicious activity is incredibly difficult for cybersecurity firms. Because the traffic originates from a legitimate household rather than a known malicious server overseas, it blends in seamlessly with everyday web browsing. Furthermore, the data flowing through these residential proxies is heavily encrypted, making it virtually impossible to inspect or decode.

Under the hood: The Pac-Man exploit

To expose the exploit, Mnemonic’s Harrison Sand rooted a Samsung smart TV’s operating system, gaining deep administrative access to monitor all incoming and outgoing network traffic. This allowed him to pinpoint exactly which applications were sharing the television’s internet connection.

His analysis revealed that the featured Pac-Man game contained resproxy code belonging to Bright Data, an Israel-based firm that sells access to millions of residential IP addresses globally. Bright Data also operates a marketplace for scraped datasets, which are compiled by utilising enlisted smart TVs as exit nodes to download vast amounts of public web data simultaneously, bypassing anti-scraping protocols.

Sand observed that while the Bright Data code loaded immediately upon opening the Pac-Man game, it did not instantly turn the television into an active exit node. Instead, the code remained dormant until the user accepted an on-screen consent prompt. Once accepted, the proxy network ran continuously in the background until the application was completely uninstalled.

Despite the requirement for user consent, Sand warned that a minor, remote code update on the developer’s server could instantly activate millions of smart TVs into a massive, potentially malicious botnet without any user intervention.

Web scraping and the proxy provider’s response

By monitoring the data packets flowing through his rooted smart TV, Sand identified that a significant portion of the traffic was being used for large-scale scraping of LinkedIn profiles and harvesting data to train AI systems. However, he noted that this represented only a fraction of the total traffic routed through Bright Data’s network.

Bright Data did not immediately respond to requests for comment. However, following the publication of the research, the company’s Chief Marketing Officer, Yanay Sela, stated that the firm maintains “the highest standards of compliance, security, and ethical use” regarding its proxy services. Sela asserted that Bright Data conducts rigorous customer identity verification and actively monitors its network to prevent malicious exploitation.

When pressed on the specifics, Sela declined to disclose the exact percentage of paying clients that have been suspended or banned for abusing the network, stating only that they represented a “small fraction” of their user base.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *