Executive Summary
In July 2026, LG Electronics USA announced plans to suspend smart TV applications that transform televisions into residential proxy nodes. This decision followed research indicating that over 42% of apps available on LG's webOS store incorporated software development kits (SDKs) enabling third parties to route internet traffic through users' TVs. Such practices raised significant privacy and security concerns, as they allowed external entities to utilize home networks without explicit user consent. LG's proactive stance aims to eliminate these unauthorized proxy functionalities and enhance user trust in their smart TV ecosystem.
This incident underscores the growing trend of embedding residential proxy capabilities into consumer devices, often without transparent disclosure. The prevalence of such practices highlights the need for stringent app review processes and increased consumer awareness regarding the potential misuse of household devices for unauthorized network activities.
Why This Matters Now
The integration of residential proxy SDKs into consumer devices poses immediate privacy and security risks, emphasizing the urgency for manufacturers to enforce stricter app review policies and for consumers to remain vigilant about the applications they install on their devices.
Attack Path Analysis
Attackers exploited smart TV applications embedding residential proxy SDKs to gain unauthorized access to users' home networks. This allowed them to escalate privileges, move laterally within the network, establish command and control channels, exfiltrate sensitive data, and potentially disrupt services.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited smart TV applications embedding residential proxy SDKs to gain unauthorized access to users' home networks.
MITRE ATT&CK® Techniques
Valid Accounts
Proxy
User Execution
Windows Management Instrumentation Event Subscription
Credential Dumping: LSASS Memory
Impair Defenses: Disable or Modify Tools
Non-Standard Port
Acquire Infrastructure: Domains
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Security of Network and Information Systems
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Consumer Electronics
Smart TV supply-chain compromise through residential proxy SDKs creates significant consumer privacy risks and regulatory compliance challenges across manufacturing ecosystem.
Entertainment/Movie Production
Smart TV proxy infiltration threatens content delivery security, viewer privacy, and intellectual property protection through unauthorized traffic routing and monitoring.
Telecommunications
Residential proxy networks in smart TVs bypass network security controls, enabling lateral movement and encrypted traffic exfiltration through compromised endpoints.
Computer Software/Engineering
App developer monetization through proxy SDKs creates supply-chain vulnerabilities requiring enhanced zero trust segmentation and egress security enforcement.
Sources
- LG to Ban Residential Proxies from Smart TV Appshttps://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/Verified
- Nearly Half of LG Smart TV Apps Contain Residential Proxy SDKshttps://spur.us/blog/smart-tv-apps-residential-proxy-sdksVerified
- 42% of LG smart TV apps sell your internet connection to strangers: LG says no morehttps://cybernews.com/security/lg-plans-suspend-residential-proxy-smart-tv-apps/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial access may still occur, the attacker's ability to exploit the compromised device would likely be constrained.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing their access to critical network resources.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely be constrained, limiting their reach to other devices.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels would likely be constrained, reducing their persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing the risk of data loss.
The attacker's ability to disrupt services or deploy malware would likely be constrained, reducing the overall impact of the attack.
Impact at a Glance
Affected Business Functions
- App Store Management
- User Privacy Compliance
- Platform Security
- Customer Support
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of user IP addresses and network traffic data through unauthorized proxy usage.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict device-to-device communication within the home network.
- • Deploy East-West Traffic Security measures to monitor and control internal network traffic.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual network activities.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent unauthorized data exfiltration.
- • Regularly audit and update smart TV applications to ensure they do not contain unauthorized proxy functionalities.



