Skip to content
Tech News
← Back to articles

Samsung bans smart TV apps that share users’ internet connections with strangers

read original more articles
Why This Matters

This discovery highlights significant security vulnerabilities in smart TV applications, exposing millions of users to potential cyber threats such as hijacking and unauthorized data interception. Samsung's response to ban and remove such apps underscores the importance of rigorous app vetting and security measures in consumer electronics. For consumers, this emphasizes the need for vigilance when installing apps and the ongoing risks associated with connected devices in smart homes.

Key Takeaways

Several popular Samsung smart TV apps contain code that share the owner’s internet connection with strangers, potentially putting millions of Samsung smart TVs at risk of hijacking, according to new security research published on Monday.

Some of these apps claim to have been installed on hundreds of millions of smart TVs in people’s homes, per the app developers.

At least one of the smart TV apps was a simple Pac-Man game that Samsung had endorsed and prominently featured in its “Editor’s Choice” section on customers’ TV screens.

These apps contain software that funnels outsiders’ web traffic through ordinary home and office internet connections, known as residential proxy networks (or “resproxies”), which are increasingly being linked to cybercrime. When opened, apps with resproxy code can turn the smart TV into an always-on tunnel for outsiders to funnel their web traffic through, known as an exit node — even when the app is no longer open.

The security research by Norwegian cybersecurity company Mnemonic describes a perfect storm of problems that allows low-quality apps to proliferate across Samsung’s app store, containing code that puts users at risk of having their internet connections tapped by a rogue app.

Many of these apps are barebone shells, made from only a few lines of code, and are designed solely to load content from another website, such as a game. While such smart TV apps load content from another server, any review of these apps sees only the few lines of code within, and not necessarily the content itself.

“What was reviewed is not necessarily what is running,” wrote Harrison Sand, an offensive security consultant at Mnemonic.

After TechCrunch contacted Samsung with a request for comment about the research, the electronics giant said in an emailed statement that it was banning apps that share their users’ internet connections, and will remove apps that contain the functionality.

“We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform,” said a Samsung spokesperson. “We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components.”

The move comes after LG said last month that it would ban apps that contain resproxy software after recent reporting found that around 42% of apps on the company’s app store enlisted a smart TV into a proxy network.

... continue reading