Jessica Entwistle
July 24 2026
LG Electronics USA has announced that it will suspend any apps built for its smart TVs that turn a user's television into an always-on residential proxy node. Krebs on Security reports that the move follows research published last month showing that more than 42 per cent of games and other apps available for download on LG's webOS store allow unknown third parties to route their Internet traffic through a user's TV. The apps in question were found to be embedding residential proxy software, effectively turning consumer devices into exit nodes for commercial proxy services without clear user consent or understanding. LG's decision to ban these apps reflects growing concern about the security and privacy implications of residential proxy networks operating on consumer devices.
For UK organisations, this is a reminder that Internet of Things devices, including smart TVs, connected displays and other network-enabled equipment in offices, meeting rooms or public spaces, can introduce unexpected security and network risks. Residential proxy apps are often used by threat actors to anonymise malicious traffic, conduct credential stuffing attacks or bypass geographic restrictions, and the presence of these apps on corporate or guest networks can create legal, compliance and security exposure. The fact that these apps were widely distributed through a major manufacturer's official app store highlights the difficulty of managing risk in consumer-grade connected devices, even when those devices are deployed in business environments. Organisations may not be aware that smart TVs or digital signage in meeting rooms, reception areas or public spaces are running third-party apps, and may not have visibility into what network activity those devices are generating. This creates a gap in network monitoring, asset management and security oversight that could be exploited by threat actors or create unintended legal or compliance risk.
Organisations should review what Internet of Things devices are connected to corporate or guest networks, particularly smart TVs, digital signage or connected displays in meeting rooms, reception areas or public spaces. This includes understanding whether these devices are segmented from business networks, whether they are receiving security updates, and whether they could be introducing unexpected proxy or network relay risks. Organisations should also consider whether they have visibility into what apps or services are running on these devices, and whether device management policies include procedures for reviewing and approving third-party software. Where smart TVs or connected displays are used in business environments, organisations may wish to review whether they are configured to prevent app installation, whether they are isolated from business networks, and whether network monitoring is in place to detect unusual traffic patterns. It is also worth considering whether procurement and asset management processes include security and network risk assessments for consumer-grade IoT devices, and whether these devices are included in regular security and compliance reviews.
Source: Krebs on Security