Skip to content

The Pac-Man Game on Your TV Was Selling Your Internet Line: Samsung Recommended It in Editor's Choice

1 min read
Share
The Pac-Man Game on Your TV Was Selling Your Internet Line: Samsung Recommended It in Editor's Choice

You are playing Pac-Man on the TV. The game is free, and Samsung recommended it in the "Editor's Choice" section right there on the screen. What is written nowhere visible is that from the moment you tap accept, your home internet line becomes a tunnel through which someone unknown on the other side of the world routes their traffic.

That is the finding of Norwegian cybersecurity firm Mnemonic, published on Monday. Several popular Samsung smart TV apps contain code for so-called residential proxy networks that use the user's connection as an exit point for third-party web traffic. According to the developers themselves, some of these apps are installed on hundreds of millions of televisions.

The most uncomfortable detail is how this got through review. Many of these apps are empty shells of a few lines of code whose only job is to pull content from another server. Whoever reviewed the app saw only those few lines - not what the server would send afterwards. "What was reviewed is not necessarily what runs," wrote Harrison Sand, an offensive security consultant at Mnemonic. That says everything about the value of the review.

Sand unlocked the internals of a Samsung television and analysed all incoming and outgoing traffic. In the Pac-Man game he found code from Bright Data, an Israeli company that sells access to millions of residential networks worldwide and runs a marketplace for harvested datasets. The code, he says, lies dormant until the user accepts a consent screen - then runs in the background until the app is deleted. So you switch off the television, and the tunnel stays open.

Of the traffic he saw, a large share looked like mass harvesting of LinkedIn profiles and data for training artificial intelligence models. Sand warns about something more significant too: "a simple change of code on a web server" could suddenly turn hundreds of millions of televisions into a potentially malicious botnet. Bright Data did not respond to a request for comment.

Samsung reacted after being contacted. The company said it had already restricted new registrations of apps with proxy functionality and is working to identify and remove any such apps still in the store. A month earlier LG announced the same, after a report showed that around 42 percent of apps on its platform were enrolling the television into a proxy network. When nearly every second app on a platform does the same thing, that is no longer an individual developer's oversight.

Residential proxy networks are not illegal in themselves - they also serve to bypass censorship, and AI companies use them heavily for data collection. The problem is that the traffic looks as if it comes from an ordinary house, is encrypted and practically impossible to separate out, which means a hacker on another continent can operate from your address. The next time someone explains to you why a television needs an app store, know exactly what you are clicking on.