mediumOther

LG webOS Smart TV Residential Proxy Abuse

First seen Jul 23, 2026 · Updated Jul 23, 2026

residential-proxyiotsmart-tvwebosproxywareprivacyconsumer-device-abuse

Researchers found that over 42% of apps on LG's webOS smart TV store secretly embed residential proxy SDKs, allowing unknown third parties to route their internet traffic through consumers' TVs without clear consent. LG has announced it will ban apps that turn smart TVs into always-on residential proxy nodes. This practice exposes users' home IP addresses and bandwidth to potentially malicious or anonymized traffic routed by unknown actors.

Technical Analysis

The threat involves third-party SDKs bundled into webOS apps that convert the smart TV into a residential proxy exit node, silently relaying external internet traffic through the device's IP address and network connection. This is consistent with commercial proxyware/residential-proxy monetization schemes commonly seen in mobile and IoT app ecosystems, where developers embed SDKs (e.g., from proxy network providers) in exchange for revenue, often without adequately disclosing the behavior to end users. Because the TV's IP is used as an anonymized relay, it can be leveraged by bad actors for credential stuffing, ad fraud, scraping, or masking malicious traffic origin, complicating attribution and increasing risk exposure for the household network. There is no direct code execution or data exfiltration vulnerability described (no CVE), but the practice degrades device trustworthiness and can expose home networks to unwanted inbound/outbound connections tied to unvetted third parties. For organizations running AI agents or RAG pipelines on home or lightly segmented networks, having consumer IoT devices like smart TVs act as covert proxy nodes could allow malicious traffic to traverse the same network segment, potentially exposing agent API keys, tool-use credentials, or internal service endpoints to interception or lateral reconnaissance if network segmentation is weak.

Affected Systems

LG Electronics webOS Smart TV platform; third-party apps distributed via the LG webOS App Store containing embedded residential proxy SDKs

Indicators of Compromise

  • No specific hashes, IPs, or domains disclosed in source reporting; IOCs would be app-specific proxy SDK identifiers within webOS store listings (not enumerated in available data)

Remediation Steps

  1. 1

    Audit installed webOS apps

    Review all apps installed on LG smart TVs and remove any with unclear provenance, excessive permissions, or unexplained persistent network activity.

  2. 2

    Network segmentation

    Place smart TVs and other IoT devices on an isolated VLAN or guest network separate from work devices, agent infrastructure, and credential stores.

  3. 3

    Monitor outbound traffic

    Use network monitoring tools to detect anomalous, sustained outbound connections from smart TVs consistent with proxy relay behavior.

  4. 4

    Apply vendor updates

    Ensure LG's upcoming policy enforcement and firmware/app store updates banning proxy-enabled apps are applied promptly once available.

  5. 5

    Restrict app installation

    Limit installation of third-party or lesser-known apps on smart TVs to reduce exposure to bundled proxyware SDKs.

Industries Most Exposed

consumer electronicstelecommunicationshome networkingmedia and entertainment

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.