LIVE · cybersecurity feed
Live wire
security

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a

zeroday.news · 10d ago

LG Electronics USA has announced plans to remove smart TV applications from its webOS platform that incorporate residential proxy software development kits (SDKs). The company stated that any developers failing to comply with this directive will have their apps suspended. This decision follows research published on July 2, 2026, by the security firm Spur, which identified a significant prevalence of such SDKs in smart TV applications.

Spur's research indicated that over 42% of apps available for LG smart TVs contained SDKs that convert the television into a residential proxy node. The study also found that more than a quarter of apps designed for Samsung's Tizen operating system included similar components.

John Taylor, Senior Vice President at LG, confirmed that the company is actively collaborating with app developers to eliminate the residential proxy functionality from their webOS applications. He emphasized that the use of residential proxy networks is not an intended function for LG smart TVs. Taylor further stated that LG is committed to preventing these networks from being integrated into its smart TV apps in the future and that a review of existing applications is currently underway. The company plans to enhance its evaluation process for developer-submitted apps, including those that might incorporate residential proxy SDKs, as part of ongoing efforts to improve platform quality and user experience.

Residential proxy providers compensate app developers to include SDKs that transform a user's device into a proxy node, which is then rented to paying customers. Spur's report found these SDKs embedded in a variety of LG and Samsung smart TV apps, ranging from simple games like Pac-Man to screensavers and file utilities. For instance, a Pac-Man app from Bright Data offered users the choice between viewing advertisements or allowing their TV to serve as a residential proxy node.

Bright Data was identified by Spur as accounting for the majority of proxy SDKs across both Samsung and LG smart TVs. While proxy providers like Bright Data claim to implement rigorous "know-your-customer" processes to validate legitimate uses, often tied to content-scraping activities, and to incorporate technological safeguards to prevent customers from controlling other devices on the proxy user's local network, Spur argues that the core issue is the widespread embedding of these SDKs in devices that consumers do not typically perceive as computers and are not equipped to audit.

Spur's Trevor Sutter highlighted that a one-time consent prompt within a TV app is insufficient for meaningful transparency, ongoing control, and platform oversight. Sutter also noted the amplified risk when consent is provided by household members, such as minors, who may not be authorized to do so.

This move by LG to address residential proxy SDKs comes after the company recently faced scrutiny regarding another partnership. Earlier in July, it was reported that certain LG LCD monitors automatically install an application promoting paid McAfee antivirus subscriptions via Windows Update, without requiring user approval.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.