Skip to content
Beveiligingsnieuws

Samsung stops Smart TV proxies: why it matters

Smart TV resproxies

Samsung is taking a firm stance against apps that use users’ internet connections for third parties. Recent security research shows that some Smart TV apps contain Smart TV resproxies: code that can turn the device into a kind of relay for web traffic. This can make a device off-screen become part of a network that routes traffic via “ordinary” home or office networks.

The impact is significant because, according to developers, multiple apps may be installed on a very large number of TVs. Samsung also says it is actively blocking new app registrations and removing apps with this functionality.

What are Smart TV resproxies?

Smart TV resproxies are technologies where a Smart TV’s (or other consumer devices’) internet connection is used as an “exit” for someone else’s traffic. In practice, this means that when the app is running, the device can forward connections as if the traffic originated from the owner’s network.

In the investigated scenario, the logic works like this: an app with resproxy code can make the TV act as an “exit node.” This role handles requests through the device, even after the app itself is no longer visibly active. As a result, the risk continues as long as the functionality remains enabled.

Why this is hard to detect

The research describes that resproxy networks are often attractive to attackers and for spying because the traffic on the internet level appears to come from a random household. That’s exactly the kind of pattern you normally wouldn’t associate with malicious activity.

In addition, traffic routed through resproxies is often encrypted. This makes inspection and unraveling difficult, especially if you can’t examine the device software in depth.

“What you see isn’t what’s actually happening”

Another issue: some apps consist of very little code and mainly load content from external servers. That can make the app look harmless in short reviews, while the real functionality only kicks in after the app is in use. One of the findings is that a verified app doesn’t necessarily show what is truly happening in the background.

From game app to proxy infrastructure

The research highlights an example that draws extra attention: a simple Pac-Man-like game recommended by Samsung in the TV’s “Editor’s Choice” section. The app included resproxy code from a third party that offers proxy networks for activities including scraping and data collection.

According to the researchers, the functionality doesn’t always start immediately. The resproxy code might, for example, only become active after the user accepts a consent screen. Once that consent is given, the resproxy functionality can keep running in the background until the user removes the app.

What’s particularly worrying is that the researchers point out a relatively small change on an existing web server can suddenly activate functionality in already published apps. In other words: a backend change can enable functionality on a huge number of devices at once.

Samsung: prohibit, block, and remove

After contacting Samsung about the findings, the manufacturer said in a response that it will ban apps that share users’ internet connections. Samsung also reports that it will actively remove existing apps that include this functionality.

In its statement, Samsung says it has already limited new app registrations for cases where proxy functionality is built in. It also works on stricter platform rules for developers, aimed at explicitly prohibiting Smart TV resproxies-related software development kits.

This approach matches a pattern we often see in app store security: not only cleaning up existing apps, but especially stopping the inflow of new risky applications.

Why this goes beyond Smart TV

The researchers don’t treat resproxies as an isolated issue. They describe that similar code can also appear in other consumer software, such as smartphone apps and other devices that use internet connections continuously or periodically (for example, streaming hardware or digital lists).

This broadens the security challenge: the same mechanism can affect multiple types of endpoints. If more devices at home (or on site) enable the same kind of functionality, it creates a larger playground for abuse.

Resproxies aren’t always “malicious”

Important nuance: resproxies are not automatically illegal by themselves. Some parties use them to reroute internet traffic for legitimate purposes, such as bypassing geographic restrictions or responding to censorship.

Even in the AI space, resproxies could be used to collect data at scale—enabling training or enrichment objectives. The problem, however, is that security firms report that resproxies are increasingly being tied to cybercrime and data incidents.

So the tension lies in both intent and control: what is an instrument for one party can become a sneaky backdoor for another to hide activities.

What can you do as a user?

You can’t always directly see resproxies from your user interface. Still, a few practical steps can help reduce risk.

  • Be critical of consent prompts in TV apps. If an app requests permission for functionality you don’t expect, don’t automatically accept.
  • Remove apps you don’t need. If resproxy functionality keeps running in the background until you uninstall, cleaning up immediately is effective.
  • Keep your apps and TV software up to date. Platform policy updates and security checks often block risky functionality earlier.
  • Review recommendations with extra attention. Just because an app is prominently featured doesn’t automatically mean it’s transparent or fully safe.

Why this incident is a wake-up call

This case shows how quickly “normal” consumer experiences can turn into a building block of infrastructure. A TV app can look small and harmless, yet still enable the device as a relay point for unknown actors through resproxies.

For organizations and households, the lesson is clear: cybersecurity doesn’t stop at the laptop. Endpoints at home and at work—especially devices that run apps and are always connected—deserve the same attention to app reputation, allowed functionality, and removability.

Finally, Samsung’s response shows that platforms can take action. But the core remains: only a combination of stricter policy, better developer management, and user awareness will truly reduce the risks around Smart TV resproxies.

More to read: proxies, network risk, and incident readiness

Want to dive deeper into what makes attacks like this possible and how defense should prepare for rapid activation and hidden behavior? Then also check out