Overview
- Security firm Mnemonic found several Samsung TV apps that include residential proxy code which can funnel outsiders' web traffic through a user's home connection.
- The proxy component typically stays dormant until a user accepts an in-app consent prompt, then runs in the background until the app is uninstalled.
- Researchers showed many affected apps are thin 'shell' wrappers that load remote content, a design that lets proxy functionality evade standard app-store review.
- Samsung has restricted new app registrations with proxy functionality, said it will remove affected apps from its store, and is implementing platform-wide developer rules banning resproxy SDKs.
- The issue raises risks for user privacy and abuse attribution, researchers warned a simple server-side change could scale activation, and other makers such as LG have announced similar bans.