What the researchers found in the store
The Norwegian security firm Mnemonic examined apps distributed through Samsung's smart TV platform and found software that creates a residential proxy network. Once such an app runs, an outside party can route their internet traffic through the television's home or office connection. The most uncomfortable single finding was where the code turned up: in a Pac-Man title that Samsung itself had promoted in the Editor's Choice section of its recommended apps, carrying code from Bright Data, a proxy provider based in Israel. Some of the apps involved claimed installation on hundreds of millions of smart TVs.
Samsung's response is unusually specific for a vendor statement. The company said it has already restricted new app registrations that incorporate proxy functionality on its Smart TV platform, that it is implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and that it is working to identify and remove all apps currently in its store that contain these components. Three commitments, each verifiable in time, which is more than these statements usually offer.
This is also not the first platform to act. LG said in July that it would suspend apps capable of turning a customer's television into a residential proxy, following reporting that indicated roughly 42 percent of the apps on its platform carried that functionality. That figure is the part worth sitting with. When two of the largest television platforms in the world are both affected at that scale, the correct conclusion is not that one vendor was careless.
Why a television is the ideal host
The mechanics: a residential proxy service sells access to IP addresses that look like ordinary consumers, because traffic from a household address passes checks that traffic from a data centre fails. Buyers use them for ad verification and price scraping, and also for credential stuffing, fraud and evading geographic restrictions. The supply side is the problem: someone has to provide the addresses, and the cheapest way to get them is to embed an SDK in free software that users install voluntarily.
A smart TV is close to the perfect host for that arrangement. It is powered on or in standby almost permanently, so it is available around the clock. Its apps update on their own schedule and its firmware is patched rarely and often not at all after a few years. It has a fast connection and no user watching a task manager. Above all, nobody in the organisation considers it a computer, so it appears in no asset register, no vulnerability scan and no offboarding checklist. It sits inside the trusted network because someone in facilities plugged it into the nearest port.
The honest version of the risk: this is not an attacker breaking in. It is a commercially operated service using a screen you bought, through an app someone installed, doing exactly what its code was written to do. That makes it far more durable than an intrusion, because there is no breach to detect and nothing on the network that looks anomalous. It is simply outbound traffic from a device that is allowed to make outbound traffic.
The bill arrives as your IP address
For a household this is mostly a story about bandwidth and consent. For a business it is a story about attribution, and that is a different order of problem. Every request a stranger routes through your connection leaves with your public IP address on it. You own that address in every practical sense: it is registered to your company, it appears in your partners' logs, and it is what an investigator sees.
The failure modes are unglamorous and expensive. Your address ends up on a reputation blocklist, and your legitimate mail starts landing in spam folders for reasons nobody can trace. A payment provider or a customer's web application firewall begins throttling or rejecting your traffic because that address has been seen doing credential stuffing. A partner's security team asks you to explain activity you cannot explain, because it did not come from any system you know about. In the worst case the routed traffic is criminal, the address resolves to your company, and you are the one holding the correspondence.
None of these arrive labelled as a smart TV problem. They arrive as deliverability trouble, as an unexplained WAF block, as a compliance question during a supplier review. Firms typically spend weeks chasing the wrong cause, because the device generating the traffic is not on any list of devices they believe they operate. That diagnostic gap is the real cost, and it is why the inventory step below matters more than any single vendor's cleanup.
What to do with the panels you already own
Start from the premise that the vendor fix does not reach you. Samsung's action governs new submissions, developer policy and store removals. The television mounted in your reception area, your meeting rooms, your showroom, your waiting area or your staff canteen has the app installed already, and whether the removal reaches it depends on the device checking in and applying the change. Assume it has not.
Three steps, in order of value: first, write down every internet-connected screen you own, including the ones in rooms nobody books and the ones inherited with a lease. Second, put them on a segregated VLAN or a guest network with egress restricted to what they actually need, which for a display running a signage or streaming app is a short list. Third, check your public IP ranges against the common abuse and blocklist databases, because if the traffic has been flowing you may already be listed and simply have not connected the two facts.
Then apply the general rule this incident illustrates. If a connected device runs free software and shows no advertising and charges no subscription, the revenue is coming from somewhere, and the two things it has to sell are your data and your address. That is a question worth asking at procurement, before the panel is on the wall. Where the budget allows, a display with no smart platform driven by a managed player you control is both cheaper to secure and easier to reason about, and it removes an entire category of this problem permanently.
Read next: Memory Prices Did What the Note 7 Could Not | Samsung Just Split the Fold Into Two Shapes



