Several popular Samsung Smart TV apps have been found containing code that can share users’ internet connections with outsiders, potentially exposing millions of devices to misuse, according to new research from Norwegian cybersecurity firm Mnemonic.
The researchers discovered that some apps available through Samsung’s official app store included residential proxy (resproxy) software. This technology can turn a Smart TV into an “exit node,” allowing other people to route their internet traffic through the TV owner’s home connection. In some cases, this continues even after the app has been closed, remaining active until the app is removed.
One of the apps identified was a simple Pac-Man game that Samsung had previously promoted in its “Editor’s Choice” section. According to the researchers, many affected apps are little more than lightweight wrappers that load content from external websites. Because the apps themselves contain very little code, app reviews may not detect what is ultimately delivered from remote servers.
Mnemonic researcher Harrison Sand explained that the version reviewed by an app store may not always match what eventually runs on users’ TVs, creating an opportunity for developers to introduce unwanted functionality after approval.
After being contacted about the findings, Samsung announced it is taking action against apps that include residential proxy features. The company said it has already blocked new app submissions containing proxy functionality and is introducing stricter developer policies that explicitly ban residential proxy software development kits (SDKs). Samsung also confirmed it is working to identify and remove existing apps that contain these components.





