Much like a smartphone or a PC, smart TVs are susceptible to security vulnerabilities. In one such instance, some apps on the Samsung smart TV platform have been found to have functions that could expose users’ internet connection to outsiders. That said, the South Korean tech giant has addressed the problem, confirming that it is working to make the platform more secure.
The issue was discovered by Norwegian cybersecurity firm Mnemonic, which published its findings in a report earlier this week. As per the report, the apps contain software that routes strangers’ web traffic through the user’s home internet connection. This forms what is known as a residential proxy network. Such networks are becoming increasingly linked to cybercrime, as they can mask malicious activity.

As to how such apps managed to make their way to the platform, the company explained that many of them are empty shells designed to load content from another server. This complicates the review process as the developer can easily swap out the entire app at any time.
In its report, Mnemonic highlighted one app in particular: a Pac-Man game that had been prominently featured in the Editor’s Choice section of the app store. While installing the app itself does not automatically turn a smart TV into a residential proxy exit node, it can do so at the flip of a switch. The code responsible for this is dormant until the user accepts a consent screen. Once this happens, the code will run in the background until the app is deleted.

Following this discovery, TechCrunch reached out to Samsung regarding the vulnerability, and was told that it is banning apps that share their users’ internet connections and will remove apps that feature the functionality. Moreover, the Samsung spokesperson noted that the company has already restricted new app registrations that incorporate such proxy functionalities. The brand is also implementing strict platform-wide developer policies explicitly banning residential proxy SDKs while also working to identify and remove the offending apps.
It is worth noting that the problem is not limited to Samsung. Similar apps were also found on LG’s app store, which prompted the company to ban apps that contain proxy software.
(Source: Mnemonic, TechCrunch)

