LG and Samsung Smart TVs Found Hosting Rogue Proxy Apps, Potentially Relaying User Traffic
What Happened — Security researchers discovered that nearly half of consumer‑available apps on LG’s webOS platform, and a growing set on Samsung’s Tizen OS, contain hidden residential‑proxy code. The apps silently route internet traffic through the TV’s always‑on connection, effectively turning the device into a proxy node without user consent. LG has announced it will suspend non‑compliant apps; Samsung is investigating the scope.
Why It Matters for Compliance & Audit Readiness
- Residential‑proxy misuse creates a potential data‑exposure scenario that can violate privacy regulations (GDPR, CCPA) and SOC 2 CC6 (Confidentiality) requirements.
- Continuous‑compliance programs must capture evidence that third‑party applications on consumer‑facing devices are vetted for privacy‑impact and that consent mechanisms are documented.
- Verisq’s CookiePLUS Privacy capability provides a unified view of consent, data‑flow mapping, and DSAR readiness to demonstrate compliance with privacy controls during audits.
Who Is Affected
- Consumer electronics manufacturers (smart‑TV OEMs)
- App developers targeting LG webOS and Samsung Tizen platforms
- End‑users of smart TVs in residential and small‑business environments
Recommended Actions
- Inventory all installed smart‑TV apps and cross‑reference against a vetted list of approved privacy‑safe applications.
- Update privacy policies and consent records to reflect any data‑processing performed by TV apps, capturing user consent as required by GDPR/CCPA.
- Deploy continuous monitoring of app behavior (network traffic analysis) to detect unauthorized proxy activity.
- Leverage CookiePLUS to map data flows, manage consent, and generate audit‑ready evidence of privacy controls.
Technical Notes – The proxy functionality is embedded via SDKs that request “use your IP address and free resources” permissions, persisting even when the app is closed. No CVE is associated; the issue stems from misuse of third‑party SDKs and lack of app‑store vetting. Traffic is relayed through the TV’s WAN interface, exposing the user’s IP address and potentially any unencrypted data traversing the connection. Source: ZDNet Security