Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI
A researcher has discovered that Bright Data, a company providing residential proxy services, is utilizing its iOS SDK embedded in free smart TV apps to turn these devices into web-scraping proxies for the AI industry. This allows Bright Data to leverage user bandwidth for scraping, posing a risk of increased network usage and potentially bypassing security measures. The issue highlights a concerning trend of consumer devices being repurposed for data harvesting, particularly as datacenter proxies become increasingly blocked by anti-bot defenses.
The investigation, led by Include Security and independent researcher Buchodi, revealed that Bright Data’s SDK, found in apps like Petflix and others, is used to route web traffic through user’s home internet connections. This effectively transforms smart TVs – typically left on and connected to fast networks – into exit nodes for scraping data, primarily for AI applications. The company’s business model relies on a network of over 400 million residential IPs, acquired through this SDK, and a consent-sourced pool of 150 million+ IPs. The research emphasizes that the traffic originates from the user’s home IP, not Bright Data’s, mitigating the immediate risk of compromised accounts. However, the ongoing use of these devices as scraping infrastructure raises concerns about bandwidth consumption and potential vulnerabilities.
Several smart TV app developers are listed as partners with Bright Data, including PlayWorks Digital, CloudTV, and Longvision. The findings also point to a lack of authentication within the peer channel used for scraping jobs, making it weaker than typical malware protections. The researcher noted that traffic bypasses VPN configurations on iOS devices, further complicating detection efforts. The consent screen presented by the apps, while claiming occasional use, allows for significant data transfer – up to 200GB per month – and operates across multiple devices linked through the SDK. This raises questions about the true nature of user consent and the extent to which users are aware of this activity.
Following the initial report, Google, Amazon, and Roku have taken steps to restrict background proxy SDKs within their smart TV apps, and Bright Data has removed support for these platforms. However, the company still lists Samsung’s Tizen and LG’s webOS as supported. The researcher recommends blocking the specific URLs associated with the SDK to mitigate the risk, suggesting tools like Pi-hole or NextDNS. Companies managing staff phones should also scan for these apps, recognizing that mobile connections can bypass traditional network blocks.
