
Samsung announced a platform-wide ban on residential proxy software development kits from its Tizen smart TV app store on August 3 — the same day Norwegian cybersecurity firm Mnemonic published research revealing that one of the apps bearing the company's own “Editor's Choice” endorsement had been capable of routing strangers' internet traffic through the home connections of millions of Samsung TV owners, without any meaningful indication to the user that their television had become a relay. TechCrunch's Zack Whittaker first reported Samsung's response after contacting the company for comment on the Mnemonic findings.
The offending app was a licensed Pac-Man game developed by Play.Works, a connected-TV game publisher that claims installations across more than 400 million homes. The game contained code from Bright Data, an Israel-based company that operates one of the world's largest commercial residential proxy networks.
Why Samsung's “Editor's Choice” Label Became a Security Problem
The Mnemonic research, conducted by offensive security consultant Harrison Sand, offers the clearest inside view yet of how residential proxy software ends up in consumer living rooms without setting off any of the alarms that are supposed to stop it. Sand's method was unusual: he physically rooted a Samsung smart TV by desoldering its flash chip — a technique known as chip-off flash chip extraction — to read the device's firmware directly. This gave him access to every byte of network traffic flowing in and out of the television, something impossible to achieve through ordinary app review.
What he found in the Pac-Man game was not hidden in the way malware is hidden. Bright Data's software development kit ships dormant inside the game. When the app launches, it reaches out to a configuration server operated by Play.Works and receives a JSON response telling it what to do. If that response includes "brightData": {"enabled": true}, a consent…
