Free apps are quietly turning smart TVs into web-scraping proxies for AI, according to a recent report by Include Security and independent researcher Buchodi. The issue lies in the embedded iOS SDK, which is used by Bright Data, a data business that heavily markets to the AI industry. This SDK turns devices, including always-on smart TVs, into exit nodes that relay web-scraping traffic, effectively using the user's home IP and bandwidth as a proxy. The risk is not a hacked account or stolen data, but rather the potential misuse of a home connection and its bandwidth as someone else's scraping infrastructure.
The technical evidence is compelling. The peer channel that carries scraping jobs has no real authentication, and on iOS, its traffic bypasses a configured VPN. When the app opens, the SDK contacts one of Bright Data's servers, which hands over its instructions without checking who is asking. This server then instructs the device to fetch pages from other websites, using the user's home internet connection. The researcher found that this channel has weaker security controls than those built into most malware, and the traffic can slip past a VPN and monitoring tools, even when the device is in use.
The consent gap is another concern. The opt-in screen does not accurately reflect what the SDK allows. In some apps, the screen says the device will be used 'occasionally', while the SDK settings allow up to 200 GB of traffic a month. In certain countries, the limits are even higher, and the device can keep working almost until the battery runs flat. The SDK can also tie together a person's phone and computers running the same company's apps, treating them as one user.
This is not a new model, but rather an old one scaled up. Bright Data is the successor to Luminati, which sold its free users' bandwidth as exit nodes through a paid proxy service. The demand for AI scrapers has shifted the focus to residential connections, as anti-bot defenses block scrapers coming from datacenter IPs. The report highlights the potential misuse of smart TVs as part of a larger trend in AI data harvesting.
To address this issue, the simplest step is to block the web addresses the SDK uses to connect on a home network. Companies managing staff phones can also scan for apps that carry the SDK, although this may not always be effective due to the ability to sidestep office Wi-Fi. The report emphasizes the need for ongoing vigilance and updates to blocklists as the SDK's connectivity methods may change.
This raises a deeper question about the meaning of consent in the digital age. As AI scrapers become more prevalent, the line between user consent and actual misuse becomes blurred. It is crucial to understand the implications of these technologies and take steps to protect personal privacy and security.