www.mnemonic.io Samsung Smart TVs Exposed to Internet Hijacking via Malicious Apps
Article Content
- •Samsung smart TV apps were found to share users' internet connections with outsiders.
- •The research identified residential proxy code in popular apps, including a Pac-Man game.
- •Samsung is banning affected apps and tightening developer policies to enhance security.
Security research revealed that several Samsung smart TV apps, including a popular Pac-Man game, contain code that allows users' internet connections to be shared with outsiders, potentially compromising millions of devices. These apps utilize residential proxy networks, enabling external users to funnel their web traffic through the owner's internet connection, even when the app is not actively running. The Norwegian cybersecurity firm Mnemonic conducted the research, highlighting the proliferation of low-quality apps in Samsung's app store that can bypass traditional review processes. In response to these findings, Samsung announced it would ban apps that share users' internet connections and implement stricter developer policies to prevent such functionalities. The issue reflects a broader concern regarding the security of smart devices and the risks posed by residential proxies linked to cybercrime.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Badbox 2.0 and Ipidea in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…