{"id":13441,"date":"2026-06-07T10:03:48","date_gmt":"2026-06-07T10:03:48","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/07\/free-apps-on-samsung-and-lg-smart-tvs-secretly-turning-your-devices-into-ai-proxies\/"},"modified":"2026-06-07T10:03:48","modified_gmt":"2026-06-07T10:03:48","slug":"free-apps-on-samsung-and-lg-smart-tvs-secretly-turning-your-devices-into-ai-proxies","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/07\/free-apps-on-samsung-and-lg-smart-tvs-secretly-turning-your-devices-into-ai-proxies\/","title":{"rendered":"Free Apps on Samsung and LG Smart TVs Secretly Turning Your Devices Into AI Proxies"},"content":{"rendered":"<p>    Free Apps on Samsung and LG Smart TVs Secretly Turning Your Devices Into AI Proxies<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">Free apps available on Samsung, LG, Roku, and other major smart TV platforms have been quietly enrolling millions of living room devices into a commercial residential proxy network used to scrape web data for AI training all through a consent dialog buried in a TV remote\u2019s arrow-key navigation, according to new research from Include Security.<\/p>\n<p class=\"wp-block-paragraph\">The culprit is an SDK developed by Bright Data, a Tel Aviv-based data-collection company that markets what it calls the world\u2019s largest residential proxy network, claiming 150M+ IP addresses sourced via embedded software in partner apps.<\/p>\n<p class=\"wp-block-paragraph\">When installed, the SDK silently transforms a user\u2019s connected TV (CTV) or mobile device into an exit node, routing paying customers\u2019 web-scraping traffic through the user\u2019s home internet connection.<\/p>\n<p class=\"wp-block-paragraph\">Researcher Buchodi, working alongside Include Security, explains why connected TVs are a prime target compared to smartphones: they are always plugged in, always on Wi-Fi, sit in standby 24\/7, face virtually zero corporate or MDM oversight, and are rarely attended by users.<\/p>\n<h2 id=\"h-free-apps-turning-smart-tvs-into-proxies\" class=\"wp-block-heading\"><strong>Free Apps Turning Smart TVs into Proxies<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The SDK\u2019s configuration confirms this exploitation, with idle threshold flags set to <code>ignore_screen_on: true<\/code> and <code>ignore_on_call: true<\/code> meaning a device is considered eligible to relay third-party traffic even while a user is actively watching or on a call.<\/p>\n<p class=\"wp-block-paragraph\">The monthly bandwidth <a href=\"https:\/\/cybersecuritynews.com\/kali-linux-2025-3-released\/\" target=\"_blank\" rel=\"noreferrer noopener\">default for Wi-Fi relaying<\/a> is capped at 200 GB per device, according to config values retrieved from Bright Data\u2019s own unauthenticated public endpoint at <code>clientsdk.bright-sdk.com<\/code>.<\/p>\n<p class=\"wp-block-paragraph\">The same unauthenticated config endpoint exposes a partner manifest, which researchers identified as including:<\/p>\n<ul class=\"wp-block-list\">\n<li>PlayWorks Digital \u2014 400+ CTV game titles distributed across Samsung, LG, Comcast, Roku, and Sky, reaching an estimated 250 million TV households<\/li>\n<li>CloudTV \u2014 integrated across 125+ TV brands and 15+ OEMs<\/li>\n<li>Viber Media (Rakuten) \u2014 250M\u2013820M monthly active users<\/li>\n<li>Moonfrog Labs \u2014 ~10M MAU on Teen Patti Gold alone<\/li>\n<li>Hola Networks \u2014 Bright Data\u2019s lineage parent company<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">The SDK opens a persistent WebSocket to <code>proxyjs.brdtnet.com:443<\/code>, resolving to AWS Global Accelerator IPs and presenting a TLS certificate for <code>*.luminatinet.com<\/code> Bright Data\u2019s pre-2018 corporate name was Luminati Networks.<\/p>\n<p class=\"wp-block-paragraph\">This legacy hostname serves as a direct detection pivot for defenders: any <code>luminatinet.com<\/code> or <code>brdtnet.com<\/code> traffic on a network is specifically the SDK\u2019s peer-tunnel plane, not legitimate Bright Data customer traffic.<\/p>\n<p class=\"wp-block-paragraph\">Critically, the SDK uses Apple\u2019s <code>NWParameters.requiredInterface<\/code> API to bind the data plane directly to the physical Wi-Fi or cellular interface, bypassing any user-configured VPN entirely.<\/p>\n<p class=\"wp-block-paragraph\">The control plane uses <code>CFHTTPMessage<\/code> primitives instead of <code>URLSession<\/code>, defeating standard iOS instrumentation tools. The combination ensures the SDK\u2019s most sensitive channel remains invisible to typical security monitoring layers.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/blog.includesecurity.com\/2026\/06\/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Buchodi recommends<\/a> blocking the following DNS hostnames at your router:<\/p>\n<ul class=\"wp-block-list\">\n<li><code>proxyjs.brdtnet.com<\/code><\/li>\n<li><code>proxyjs.luminatinet.com<\/code><\/li>\n<li><code>clientsdk.bright-sdk.com<\/code><\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">For TLS-based filtering, drop any handshake with SNI matching <code>*.brdtnet.com<\/code>, <code>*.luminatinet.com<\/code>, or <code>*.luminati.io<\/code>. Enterprise MDM administrators should scan for Swift binary symbols <code>BrdWebSocketFacade<\/code> and <code>BrdNetwork.DNSResolver<\/code> to identify affected apps on managed devices.<\/p>\n<p class=\"wp-block-paragraph\">Include Security notified Bright Data on May 11, 2026, via <code>privacy@brightdata.com<\/code>. No response was received prior to publication.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/free-apps-turning-smart-tvs-into-proxies\/\">Free Apps on Samsung and LG Smart TVs Secretly Turning Your Devices Into AI Proxies<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/free-apps-turning-smart-tvs-into-proxies\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Free Apps on Samsung and LG Smart TVs Secretly Turning Your Devices Into AI Proxies Free apps available on Samsung, LG, Roku, and other major smart TV platforms have been quietly enrolling millions of living room devices into a commercial residential proxy network used to scrape web data for AI training all through a consent [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-13441","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13441"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13441"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13441\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13441"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13441"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13441"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}