LG webOS Smart TV Residential Proxy Abuse
First seen Jul 23, 2026 · Updated Jul 23, 2026
Researchers found that over 42% of apps on LG's webOS smart TV store secretly embed residential proxy SDKs, allowing unknown third parties to route their internet traffic through consumers' TVs without clear consent. LG has announced it will ban apps that turn smart TVs into always-on residential proxy nodes. This practice exposes users' home IP addresses and bandwidth to potentially malicious or anonymized traffic routed by unknown actors.
Technical Analysis
The threat involves third-party SDKs bundled into webOS apps that convert the smart TV into a residential proxy exit node, silently relaying external internet traffic through the device's IP address and network connection. This is consistent with commercial proxyware/residential-proxy monetization schemes commonly seen in mobile and IoT app ecosystems, where developers embed SDKs (e.g., from proxy network providers) in exchange for revenue, often without adequately disclosing the behavior to end users. Because the TV's IP is used as an anonymized relay, it can be leveraged by bad actors for credential stuffing, ad fraud, scraping, or masking malicious traffic origin, complicating attribution and increasing risk exposure for the household network. There is no direct code execution or data exfiltration vulnerability described (no CVE), but the practice degrades device trustworthiness and can expose home networks to unwanted inbound/outbound connections tied to unvetted third parties. For organizations running AI agents or RAG pipelines on home or lightly segmented networks, having consumer IoT devices like smart TVs act as covert proxy nodes could allow malicious traffic to traverse the same network segment, potentially exposing agent API keys, tool-use credentials, or internal service endpoints to interception or lateral reconnaissance if network segmentation is weak.
Affected Systems
LG Electronics webOS Smart TV platform; third-party apps distributed via the LG webOS App Store containing embedded residential proxy SDKs
Indicators of Compromise
- No specific hashes, IPs, or domains disclosed in source reporting; IOCs would be app-specific proxy SDK identifiers within webOS store listings (not enumerated in available data)
Remediation Steps
- 1
Audit installed webOS apps
Review all apps installed on LG smart TVs and remove any with unclear provenance, excessive permissions, or unexplained persistent network activity.
- 2
Network segmentation
Place smart TVs and other IoT devices on an isolated VLAN or guest network separate from work devices, agent infrastructure, and credential stores.
- 3
Monitor outbound traffic
Use network monitoring tools to detect anomalous, sustained outbound connections from smart TVs consistent with proxy relay behavior.
- 4
Apply vendor updates
Ensure LG's upcoming policy enforcement and firmware/app store updates banning proxy-enabled apps are applied promptly once available.
- 5
Restrict app installation
Limit installation of third-party or lesser-known apps on smart TVs to reduce exposure to bundled proxyware SDKs.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.