According to the latest security research, several popular Samsung smart TV applications have been found to contain residential proxy network (resproxies) related code, which may cause users' home or office network connections to be shared with unknown third parties, putting millions of Samsung smart TVs at potential risk of being hijacked. One of the apps, a Pac-Man game recommended by Samsung and previously featured in the TV's "Editor's Choice" section, was also found to contain related code.

The research was published by the Norwegian cybersecurity company Mnemonic. Researchers pointed out that these applications are mostly simple in structure, loading content from external servers with minimal code, but their actual operation logic may include unreviewed proxy components. Security consultant Harrison Sand stated that what is seen during app reviews does not necessarily equate to what is actually running, making it possible for apps with risky code to enter the smart TV ecosystem.
The research found that some apps integrated residential proxy SDKs, which can use ordinary user devices' network connections as exit nodes to forward internet traffic for external users. Even if the app is closed, as long as the relevant components are not removed, the device may continue to participate in the proxy network. By analyzing the Samsung smart TV system and network traffic, Sand discovered that the affected Pac-Man game contained Resproxy code from the Israeli proxy service company Bright Data.
Researchers noted that residential proxy technology itself is not illegal, and AI companies also use such networks to collect public data from multiple locations for model training. However, since proxy traffic usually comes from real home networks, attackers could use this to hide their sources and carry out cyberattacks, data leaks, or bypass security restrictions.
Mnemonic further pointed out that through analysis of related network traffic, some Resproxy networks appear to have been used for large-scale scraping of LinkedIn user information and collecting AI training data. Although it has not yet been confirmed that all applications are malicious, researchers warned that if server-side code changes, the potential risks could quickly expand.
In response to this issue, Samsung stated that it has restricted new applications containing residential proxy functions from registering, and is implementing stricter platform developer policies to ban residential proxy SDKs, while cleaning up applications in the app store that contain such components. Previously, LG also announced a ban on related software, as its app store was found to have approximately 42% of applications connected to proxy networks.
This incident once again highlights new challenges faced by the smart device ecosystem's review mechanisms. As demand for AI data collection grows, the scale of residential proxy network usage increases, and how to balance data acquisition efficiency with user network security has become an issue of concern for smart terminals and the AI industry.
