LG Electronics USA will suspend webOS apps that function as residential proxy nodes, blocking users from converting their smart TVs into always-on traffic routing devices for third parties. The decision follows research revealing that over 42 percent of games and applications available on LG's webOS store permit unknown third-parties to redirect internet traffic through connected televisions.
Residential proxies route web traffic through legitimate consumer devices, masking the origin of requests. This practice enables malicious actors to circumvent security systems, conduct targeted attacks, and evade detection. When deployed across thousands of compromised devices, residential proxies become particularly effective for credential stuffing, web scraping, distributed denial-of-service attacks, and fraud.
The vulnerability in LG's app ecosystem exposed millions of households. Smart TVs typically remain powered 24/7, making them ideal infrastructure for attackers seeking stable, persistent proxies. Users often lack visibility into what permissions third-party applications request or how their device bandwidth gets consumed. The high percentage of offending apps on LG's store suggests minimal review of app permissions before distribution.
LG's suspension targets apps that explicitly enable this behavior, though the enforcement mechanism remains unclear. The company did not specify whether existing apps will be removed retroactively or if the ban applies only to new submissions. Users who already installed such applications may retain proxy functionality unless LG pushes forced updates or remotely disables the apps.
This incident underscores broader smart TV security challenges. Connected televisions collect personal data, store credentials, and consume household bandwidth, yet manufacturers historically lag behind smartphone vendors in security practices. Many smart TV apps lack code review standards comparable to those on iOS or Android platforms.
LG's action represents a rare public acknowledgment of residential proxy abuse via consumer hardware. However, the company faces pressure to enforce stricter app vetting processes going forward. Organizations and individuals should review app permissions on connected devices and consider