
Samsung is banning smart TV apps that can route strangers’ web traffic through users’ home internet connections after researchers found residential proxy software embedded in games available through its app store.
One affected Pac-Man title had even been promoted in Samsung’s “Editor’s Choice” section.
The findings were published on August 3 by Harrison Sand, a cybersecurity researcher at Norwegian security firm Mnemonic. Sand rooted a Samsung television to examine its apps, configuration files, background services, and network traffic — access that ordinary network monitoring could not provide because most communications are encrypted.
Mnemonic obtained deeper access using techniques including chip-off extraction, which involves desoldering a device’s flash storage and reading its firmware directly. The investigation found Bright Data’s residential proxy SDK inside games distributed by Play.Works, including Pac-Man and 2048 Football Cup.
Play.Works develops games for connected televisions and set-top boxes, licensing titles such as Pac-Man, Tetris, Space Invaders, and SpongeBob. The company says its portfolio includes more than 400 games installed across over 400 million households. Bright Data, formerly known as Luminati Networks, operates a large proxy network and sells datasets collected from public websites.
Residential proxy services allow customers to send traffic through ordinary household internet connections. This makes requests appear to originate from a legitimate residential IP address rather than a data center or known automated system.
Such networks can support legitimate activities, including market research, censorship circumvention, and large-scale data collection. However, they can also help attackers conceal credential theft, scraping, fraud, and other malicious activity behind an unsuspecting user’s IP address.
Mnemonic found that installing Pac-Man did not immediately turn the television into a proxy node. The Bright Data component was dormant and depended on a remotely controlled configuration setting. In 2048 Football Cup, the setting was enabled and displayed a consent screen before activating the proxy service.

Once accepted, a Tizen background service defined in the app’s config.xml file could continue operating after the user left the game. Researchers warned that children or other users might approve the prompt simply to continue playing without understanding that external traffic would be routed through the household connection.
The larger concern was that the apps acted mainly as shells that downloaded their actual code from Play.Works servers. Mnemonic found that the Pac-Man package submitted to Samsung contained roughly 20 lines of HTML that pointed to remotely hosted game content.
This architecture allows developers to update games without submitting a new store version, but it also means an app’s behavior can change after review. A server-side configuration update could enable the embedded proxy SDK without changing the package originally inspected by Samsung.
During traffic analysis, Mnemonic observed connections associated with LinkedIn, Walmart, TikTok, YouTube, Google, Microsoft, and other services. Much of the limited sample appeared consistent with web scraping and dataset collection, although the researchers stressed that they could see only a small portion of Bright Data’s overall traffic.
Following these revelations, Samsung told media that it had restricted new smart TV app submissions that contained proxy functionality. The Korean tech giant said it is also introducing policies that explicitly prohibit residential proxy SDKs and is identifying and removing existing apps that contain these components.
Bright Data said it uses identity checks, network monitoring, and other controls to prevent abuse. The company did not disclose how many customers it has suspended or terminated, describing the number only as a small fraction.
Samsung TV owners should remove unused games and apps, review unfamiliar consent prompts carefully, and check for unexpected applications running in the background. Users concerned that their connection has been shared should uninstall the affected app, restart the television and router, update the TV’s firmware, and monitor their public IP address for abuse reports or unusual service blocks.







Leave a Reply