LG to Suspend Smart TV Apps That Turn WebOS Devices into Residential Proxies
Move follows research showing over 42% of webOS store apps can route third-party traffic through users' TVs without clear consent.

Key Takeaways
- LG will suspend smart TV apps that turn devices into residential proxy nodes.
- Research found over 42% of webOS store apps allow third-party traffic routing.
- The move aims to protect user privacy and network integrity.
- No active exploitation has been reported, but the practice poses privacy risks.
- Users should review app permissions and update TV firmware.
Quick answers
- What happened?
- LG Electronics USA announced it will suspend apps on its webOS smart TV platform that function as always-on residential proxy nodes. The decision comes after researchers found that a significant portion of apps in LG's store allow unknown third parties to route internet traffic through users' TVs, raising privacy and security concerns.
- Which products are affected?
- webOS smart TVs
- What should defenders do?
- LG plans to suspend offending apps. Users should update their TV firmware, review app permissions, and uninstall apps that request unnecessary network access. Additionally, monitoring network traffic for unusual activity can help detect unauthorized proxy usage.
LG Electronics USA has announced plans to suspend any applications built for its smart TVs that turn the device into an always-on residential proxy node. The decision, reported by Krebs on Security, follows research published less than a month earlier which found that more than 42 percent of games and other apps available on LG's webOS store allow unknown third parties to route their internet traffic through a user's TV.
Residential proxies use IP addresses assigned to home users, making traffic appear as if it originates from a legitimate household. While such services have legitimate uses, they can also be abused for ad fraud, credential stuffing, or bypassing geo-restrictions. The research highlighted that many apps on LG's platform were embedding proxy functionality without transparent disclosure, effectively turning consumers' televisions into unwitting network participants.
LG's response indicates a proactive step to protect user privacy and network integrity. The company plans to suspend apps that engage in this behavior, though specific enforcement timelines and the list of affected apps have not been disclosed. Users are advised to review app permissions and keep their TV firmware updated.
This development underscores the growing trend of IoT devices being repurposed for proxy networks, often without user awareness. While no active exploitation has been reported, the practice poses significant privacy risks and could expose users to legal or security liabilities. LG's action sets a precedent for other smart TV manufacturers to scrutinize app behaviors more closely.
Security Details
LG's webOS smart TV platform allows apps to function as residential proxy nodes, routing third-party internet traffic through users' TVs without transparent consent. Research indicates over 42% of apps in the store have this capability. While no active exploitation is reported, the practice can expose users to privacy violations and potential misuse of their network resources.
Affected products
webOS smart TVs
Mitigation
LG plans to suspend offending apps. Users should update their TV firmware, review app permissions, and uninstall apps that request unnecessary network access. Additionally, monitoring network traffic for unusual activity can help detect unauthorized proxy usage.
Sources
Krebs on Security
LG to Ban Residential Proxies from Smart TV Apps
Jul 22, 2026 · 01:10
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

OpenAI AI Agents Accidentally Upload User Images to Third-Party Sites
OpenAI has confirmed that its AI agents inadvertently uploaded user-provided images to external image-hosting services while performing research and evaluation tasks. The incident raises privacy concerns for users who provided images to ChatGPT and related AI services during the affected period.


