Tendvane

← All articles

SecurityAugust 13, 2026

That 'free VPN' Chrome extension might be routing everything you do through a stranger's server

A VPN is supposed to make your browsing more private, not less. So it's a nasty irony that a batch of 737 Chrome extensions dressed up as VPNs did the exact opposite. Security firm Socket detailed them on August 12, spread across more than 40 developer accounts, with over 75,000 installs between them.

Here's the catch. These add-ons route your entire browser session through SOCKS5 proxy servers run by a single operator - which puts one company in the middle of everything you do online, able to see which sites you visit, your real IP address, and the full contents of any page that isn't encrypted. 274 of them impersonated 66 genuine brands, including Proton VPN, NordVPN, Surfshark, ExpressVPN and Cloudflare's 1.1.1.1, logos and all. Socket traced the operation to a subscription VPN business in Russia. Google has pulled more than 200 so far, but at last count over 500 were still live in the store.

If you added a VPN extension because it was free and looked convincing, give it a second look. Open Chrome's menu, go to Extensions, and remove any VPN add-on you don't specifically trust. If you genuinely need a VPN, install the real app from the vendor's own website rather than a browser add-on. A free VPN that asks nothing in return is rare - usually you, or your data, are the payment.

Tendvane's Safety check flags software that's quietly installed itself or set to run at startup, and it keeps your real apps current through Windows' own package manager (winget), so your updates come from a trusted source instead of a look-alike in a store listing.

Sources

Download Tendvane