[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fJdgUd98lmkeaU7ELU7A-rPBPchD5rrp8dEdEgd1dkbw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"2f8bde0e-422e-43d6-810a-4323988f91a9","residential-proxy-sdks-in-smart-tv-apps-expose-users-to-hidden-traffic-routing","996bcef8-fc0b-426b-8aeb-97bff3cc0d98","Residential Proxy SDKs in Smart TV Apps Expose Users to Hidden Traffic Routing","Third-party SDKs embedded in LG webOS smart TV apps were silently routing internet traffic through users' home networks without their knowledge or consent, effectively turning consumer devices into residential proxy nodes. This is a supply chain risk because app developers introduced malicious or privacy-violating components through third-party SDK integrations, bypassing platform-level oversight. The issue highlights the danger of insufficient vetting of third-party libraries before they reach an app marketplace. Users had no visibility into this behavior, meaning their bandwidth, IP reputation, and potentially sensitive network data were being exploited. Platform owners like LG bear responsibility for enforcing SDK policies before apps reach consumers.","**Immediate actions:**\n- Audit all published apps in your platform or ecosystem for unauthorized or privacy-violating third-party SDKs.\n- Suspend or quarantine any app confirmed to contain residential proxy or covert traffic-routing SDKs pending remediation.\n- Notify affected users about the data exposure risk and steps being taken to resolve it.\n\n**Long-term improvements:**\n- Establish a mandatory SDK\u002Fthird-party library vetting process as part of app submission review before marketplace approval.\n- Require developers to submit a Software Bill of Materials (SBOM) for all apps listing every third-party dependency.\n- Implement contractual developer agreements that explicitly prohibit SDKs that route user traffic without informed consent.\n\n**Detection measures:**\n- Deploy continuous automated scanning of marketplace apps to detect known malicious or privacy-violating SDKs post-publication.\n- Monitor platform network telemetry for anomalous outbound traffic patterns indicative of proxy or relay behavior.\n- Establish a responsible disclosure or bug bounty program to incentivize external researchers to report SDK abuses.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management Practices","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 AC-4: Information Flow Enforcement","GDPR Article 5(1)(a): Lawfulness, Fairness and Transparency","GDPR Article 25: Data Protection by Design and by Default","NIST CSF PR.DS-5: Protections Against Data Leaks","OWASP Mobile Top 10: M8 - Security Decisions via Untrusted Inputs","published","2026-07-22T02:20:24.869789+00:00","2026-07-22T02:20:24.726+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fkrebsonsecurity.com\u002F2026\u002F07\u002Flg-to-ban-residential-proxies-from-smart-tv-apps\u002F","lg-to-ban-residential-proxies-from-smart-tv-apps-127a68","LG to Ban Residential Proxies from Smart TV Apps",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]