Jessica Entwistle
July 22 2026
LG Electronics USA has announced it will suspend apps on its smart TV platform that turn users' televisions into residential proxy nodes. Krebs on Security reports that the decision follows research showing more than 42% of apps available on LG's webOS store allow unknown third parties to route internet traffic through users' TVs without clear disclosure or informed consent. Residential proxy networks are commonly used by cybercriminals, fraudsters and bot operators to disguise their activity by routing traffic through legitimate consumer devices, making malicious requests appear to originate from residential IP addresses. This technique is used to bypass security controls, evade detection and make attribution more difficult. LG's move to remove these apps represents a significant policy shift for a major consumer electronics manufacturer and raises broader questions about the security and transparency of apps available on smart TV platforms and other consumer IoT devices.
For UK organisations, the relevance of this story extends beyond consumer devices. Many businesses have smart TVs in meeting rooms, reception areas, breakout spaces and executive offices, often connected to corporate networks for video conferencing, presentations or digital signage. If those devices are running apps that operate as residential proxies, they may be routing third-party traffic through the organisation's network without IT's knowledge or consent. This creates potential legal, compliance and security risks, particularly if that proxied traffic is used for malicious purposes and appears to originate from the organisation's IP space. It also raises broader questions about the security and transparency of IoT devices in corporate environments, and whether organisations have visibility into what those devices are actually doing once connected to the network. Consumer IoT devices such as smart TVs, digital signage, voice assistants and connected appliances are often deployed in corporate environments without the same level of security scrutiny, configuration management or monitoring that would be applied to traditional IT assets. These devices may have default credentials, unpatched firmware, unnecessary services enabled or apps installed that introduce risk without IT's awareness. The fact that a significant proportion of apps on a major smart TV platform were operating as residential proxies without clear disclosure suggests that the security and privacy standards for consumer IoT apps are not well enforced or understood.
UK organisations should review what smart TVs, digital signage and other consumer IoT devices are connected to corporate networks, what apps are installed on those devices, and whether there is any policy or technical control preventing them from running unauthorised services. Consider conducting a network scan to identify IoT devices, review their configuration and assess whether they are segmented from core business systems. Organisations should also consider whether network monitoring would detect unusual outbound traffic patterns from these devices, and whether they should be isolated on separate network segments with restricted internet access. Where smart TVs are used in corporate environments, review who has administrative access to those devices, whether app installation is controlled, and whether the devices are included in asset management, patching and security monitoring processes. Consider implementing a policy that requires IoT devices to be registered, approved and configured according to security standards before being connected to corporate networks, and ensure there is visibility into what those devices are doing once deployed. Organisations should also review whether consumer IoT devices are covered by acceptable use policies, incident response plans and network security controls, and whether there is a process for reviewing and removing unnecessary apps or services from those devices.
Source: Krebs on Security