The apps were near empty shells that loaded their real content from a remote server, so app reviewers never saw the code that turned the TV into a relay for strangers' web traffic.
A Pac-Man game that Samsung had placed in its own "Editor's Choice" shelf on the smart-TV app store was, in practice, routing strangers' web traffic through the home internet of anyone who installed it. The game was one of several Samsung TV apps discovered to contain code that turns the television into a relay for outside internet activity, even after the app is closed.
The affected apps' developers claim combined installs in the hundreds of millions of TVs, according to research published Monday by Norwegian security firm Mnemonic. Many of the apps are bare-bones shells: a few lines of code that load a game or other content from a remote server. App reviewers saw only the shell, not what the shell fetched. "What was reviewed is not necessarily what is running," said Mnemonic offensive security consultant Harrison Sand.
Samsung, contacted by TechCrunch, said it is acting: "We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform. We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components."
LG announced a similar ban last month, after reporting that around 42% of apps on its smart-TV store contained residential-proxy code. The technology has become a fixture of the criminal internet, used for credential stuffing, ad fraud, and bypassing geo-restrictions. Samsung's ban applies to new app submissions now; existing apps are still being audited.