Skip to content
← All news
4 min read

LG will ban webOS apps that quietly turn your TV into a stranger's proxy

Security firm Spur found Bright Data's proxy SDK inside 367 webOS apps, routing strangers' internet traffic through people's living rooms. LG is now suspending apps that carry it.

367 ordinary smart TV apps were secretly turning living rooms into internet proxies for strangers.

LG says it will suspend webOS app-store apps that bundle residential-proxy SDKs, code that quietly turns a smart TV into an always-on relay for someone else's internet traffic. The trigger is research from the security firm Spur, which found the practice baked into hundreds of ordinary apps, games and screensavers included.

What a residential-proxy SDK actually does

A residential-proxy network sells access to real home IP addresses, the kind that look like an ordinary person's internet connection instead of a data center's. Companies pay for that access because traffic that looks like it is coming from a real household is harder to block and easier to trust than traffic from a known proxy service. The SDK is how a device gets recruited into that network: bundle it into an app, and every install becomes another IP address for sale, routing strangers' traffic through that person's home connection in the background.

How big the problem is

Spur, credited to researcher Trevor Sutter, published its findings on July 2, 2026, and the number that stands out is 367: the count of webOS apps found carrying a residential-proxy SDK, chiefly Bright Data's 'Bright SDK.' Spur's complaint is not that the technique exists, it is how it ships: no "meaningful transparency, ongoing control, or platform oversight," in Spur's words, for the person whose TV and home connection actually get used. Samsung's Tizen platform has the same problem at larger scale, over a quarter of its apps by Spur's count, though Samsung has not announced a ban of its own.

What LG is actually doing about it

LG senior VP John Taylor confirmed the company is "strengthening our evaluation process for developer-submitted apps" and working directly with developers to strip the proxy code out, suspending any app that does not comply. LG can actually enforce that, because it controls the one thing a developer needs: a listing in its app store. Bright Data, named as the dominant vendor here, defends its model as opt-in and disclosed, which is a fair distinction between the SDK vendor's terms and what actually reaches the end user buried in an app's fine print.

Why a build studio cares

The uncomfortable part of this story is how ordinary the entry point is: a free game or a screensaver, the kind of low-stakes app nobody audits closely before shipping to a TV platform. If we are ever building or reviewing an app for a client on a smart TV, streaming box, or any SDK-heavy platform, this is now a standing line item: read what every bundled SDK actually does on the device instead of trusting what it claims to do in its own docs, and assume a user's bandwidth and IP reputation are assets worth stealing quietly rather than loudly.

Next step: read Krebs on Security's report for LG's full statement, and Cybernews' coverage for the platform-wide numbers. If you are shipping to a smart TV or embedded platform and want a second set of eyes on what the SDKs in your build are actually doing, write to us at hello@gattyworks.com.

Smart TVPrivacySecurityLGBrightDataResidentialProxySmartTVwebOSDataPrivacyCyberSecurityIoTSecurityConsumerPrivacyAppSecurity

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.