Samsung Bans Risky Smart TV Apps Over Hijacking Threat
Samsung is removing several smart TV applications from its platform following cybersecurity research that exposed a hidden threat: some apps were secretly converting user internet connections into tools for cybercriminals. Norwegian cybersecurity firm Mnemonic discovered the vulnerability, prompting Samsung to act fast.

How the Hijacking Works

The apps in question contained residential proxy software. This software turns a user’s home internet connection into a “residential proxy” network. Cybercriminals exploit these networks to hide their own online activities, making their traffic appear to come from ordinary households rather than malicious servers.

The scale is troubling. Because the traffic originates from real homes, it’s encrypted and difficult for security firms to detect. A single app on millions of Smart TVs could instantly create a massive botnet.

What Samsung Found and Did

Samsung confirmed it has stopped accepting new Smart TV apps containing proxy functionality. A company spokesperson stated: “We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform. We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs.”

The company is now identifying and removing existing apps that violate this new policy. This move mirrors action taken by LG weeks earlier, after reports showed nearly half of LG’s smart TV apps contained similar proxy software.

A Game That Wasn’t Just a Game

One striking discovery involved a Pac-Man game that was previously an “Editor’s Choice” on Samsung’s platform. The game included code from proxy network provider Bright Data. The software ran silently in the background after users granted permission, and continued running even after the game closed.

Users effectively turned their televisions into internet exit nodes without knowing it. This illustrates a critical vulnerability in how Smart TV app reviews work.

The Real Problem: Apps Change After Review

Security consultant Harrison Sand from Mnemonic flagged a deeper issue. Many Smart TV apps load content from external servers. This means the app Samsung reviewed at launch may not be the same code running on users’ TVs months later.

What was reviewed is not necessarily what is running, Sand explained. A simple server-side code update could activate proxy functionality across millions of devices instantly. During his investigation, Sand observed network activity consistent with large-scale web scraping and AI model training running through residential connections.

What Smart TV Owners Should Do Now

The immediate steps are straightforward but important:

  • Review and uninstall any unnecessary or unfamiliar apps, especially older games or little-known applications
  • Avoid granting permissions to apps without understanding their purpose
  • Keep your Smart TV updated with the latest firmware
  • Only download apps from trusted developers

The Bigger Picture

This incident underscores a critical reality: everyday devices like Smart TVs require the same security awareness as smartphones or computers. Most households treat their TV as a dumb appliance, not as a connected device with full internet access and camera permissions. That assumption is no longer safe.

Samsung’s response is necessary but reactive. The real protection comes from users staying vigilant about what apps they install and what permissions they grant. Until app stores can guarantee that reviewed code matches deployed code, Smart TV owners are the final line of defense against hijacking.

Follow Hashlytics on Bluesky, LinkedIn, Telegram and X to Get Instant Updates