Several popular Samsung smart TV apps contain code that share the owner’s internet connection with strangers, potentially putting millions of Samsung smart TVs at risk of hijacking, according to new security research published on Monday.
Some of these apps claim to have been installed on hundreds of millions of smart TVs in people’s homes, per the app developers.
At least one of the smart TV apps was a simple Pac-Man game that Samsung had endorsed and prominently featured in its “Editor’s Choice” section on customers’ TV screens.
These apps contain software that funnels outsiders’ web traffic through ordinary home and office internet connections, known as residential proxy networks (or “resproxies”), which are increasingly being linked to cybercrime. When opened, apps with resproxy code can turn the smart TV into an always-on tunnel for outsiders to funnel their web traffic through, known as an exit node — even when the app is no longer open.
The security research by Norwegian cybersecurity company Mnemonic describes a perfect storm of problems that allows low-quality apps to proliferate across Samsung’s app store, containing code that puts users at risk of having their internet connections tapped by a rogue app.
Many of these apps are barebone shells, made from only a few lines of code, and are designed solely to load content from another website, such as a game. While such smart TV apps load content from another server, any review of these apps sees only the few lines of code within, and not necessarily the content itself.
“What was reviewed is not necessarily what is running,” wrote Harrison Sand, an offensive security consultant at Mnemonic.
After TechCrunch contacted Samsung with a request for comment about the research, the electronics giant said in an emailed statement that it was banning apps that share their users’ internet connections, and will remove apps that contain the functionality.
“We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform,” said a Samsung spokesperson. “We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components.”
The move comes after LG said last month that it would ban apps that contain resproxy software after recent reporting found that around 42% of apps on the company’s app store enlisted a smart TV into a proxy network.
Inside a residential proxy network
The research also offers a rare look inside a residential proxy network.
Resproxy code can also be found in regular consumer phone apps, as well as other consumer electronics, like digital frames and Android streaming boxes, which then share that device’s internet connection.
Any time a resproxy app or device connects to the internet, an outsider can also pay to use it.
Resproxies are not inherently illegal. Some are used for evading censorship by routing internet traffic through ordinary looking residential homes. AI companies, for example, increasingly rely on resproxies to scrape data from multiple places on the internet in one go to train their AI models.
But cybersecurity companies say resproxies have gained a reputation for allowing hackers and spies to carry out cyberattacks and data breaches while hiding their malicious activity.
Cybersecurity companies find resproxies challenging to tackle because the network traffic looks like it’s coming from an ordinary household, rather than a malicious hacker located overseas, as they might expect.
Moreover, the network traffic that flows through a user’s device over resproxies is generally encrypted, which is generally impossible to unscramble and inspect.
By rooting a Samsung smart TV’s software, Mnemonic’s Sand gained deep access to the television’s internals and analyzed all of the network traffic that flowed in and out of the TV. This included any app that was sharing the smart TV’s internet connection with someone else.
He found the Pac-Man game contained resproxy code from Bright Data, an Israel-based company that provides proxy networks touting access to millions of residential networks around the world. The company also has a marketplace for selling access to scraped data sets. These datasets are derived from a network of enlisted smart TVs as exit nodes, which are used to download large amounts of public data from the web from multiple sources at once, often to circumvent systems designed to prevent scraping.
Sand found that Bright Data’s resproxy code loaded when opening the Pac-Man game, but noted that this did not automatically turn the Samsung smart TV into an exit node. Sand said the resproxy code is dormant until the user accepts a consent screen, which immediately activates the resproxy code to run in the background until the user deletes the app.
Aside from the user themselves consenting to enlisting their device into a resproxy, Sand warned that a “simple code change on a web server” could instantly activate hundreds of millions of smart TVs into a potentially malicious botnet.
With access to the network data flowing through his smart TV, Sand could see that much of it appeared to suggest the resproxy network was used for large-scale scraping of LinkedIn profiles, and for collecting AI training data. Sand said he only saw a tiny percentage of what was routed over Bright Data’s network.
Bright Data did not respond to a request for comment.