Also on CyberFence: compare CyberFence to other VPNs side-by-side · the free CyberFence security tools .

Stressed man in casual shirt looking at laptop screen showing a security alert popup in home office with natural window light and lamp

Security researchers disclosed this week that 737 free VPN and proxy extensions in the Chrome Web Store were secretly routing users' browser traffic through proxy infrastructure controlled by unknown third parties. Spread across at least 40 developer accounts and accumulating more than 75,000 installs, 274 of these extensions specifically impersonated 66 legitimate, well-known VPN brands — including names that users actively search for and trust.

If you've installed a free VPN extension in Chrome, this is the moment to audit what you actually have. Here's what these extensions were doing, how they work, and how to tell a real VPN from one designed to surveil you.

What These Extensions Were Actually Doing

The extensions presented as free VPN tools with the standard privacy promises: hide your IP address, encrypt your traffic, access blocked content. What they were actually doing was different:

  • Routing browser traffic through proxy networks — instead of encrypting traffic and sending it to a VPN server the extension controls, traffic was routed through third-party proxy infrastructure. The operators of that proxy network could monitor what sites users visited, intercept unencrypted requests, and potentially modify content in transit.
  • Intercepting browser traffic — extensions with access to browser traffic can read URLs, form submissions, and in some cases the content of pages the user visits, depending on the extension's permissions and how HTTPS is handled at the proxy level.
  • Impersonating legitimate brands — 274 of the 737 extensions specifically mimicked the names, icons, and interfaces of 66 real VPN providers. Users who searched for a known VPN brand and installed one of these impersonators believed they had the real product.

The primary targets appeared to be Russian-speaking users seeking to bypass content restrictions — a population that actively searches for free VPN tools and may be less familiar with distinguishing legitimate from malicious extensions. But the proxy infrastructure affected any user who installed the extensions regardless of location.

Why Free Browser Extensions Are a Privacy Risk by Design

The 737 malicious extensions are an extreme example of a general problem with free browser extensions: the business model almost always involves your data.

Legitimate browser extensions that provide real VPN functionality are rare for a technical reason: a browser extension can only protect traffic that passes through the browser's own web request system. It cannot encrypt traffic from your operating system's network stack, from other apps running on your device, or from the browser's internal connections to services like Google Safe Browsing.

A real VPN — a system-level VPN application — creates an encrypted tunnel at the operating system level that captures all network traffic from all applications, not just browser tabs. A browser extension labeled "VPN" is fundamentally not doing the same thing as a VPN app, regardless of what it says on the Chrome Web Store listing.

What a browser extension can do is route your browser traffic through a proxy. That proxy may or may not encrypt traffic, may or may not log what you do, and is operated by whoever controls the infrastructure the extension connects to — which in the case of these 737 extensions, was unknown third parties.

A Real VPN — Not a Browser Extension

CyberFence is a system-level VPN app for iPhone, iPad, Android, Mac, and Windows. It encrypts all traffic from all apps on your device — not just browser tabs — with AES-256-GCM encryption. Zero logs, US-operated.

See Plans →

The Brand Impersonation Problem

Of the 737 extensions identified, 274 specifically impersonated 66 real VPN brands. This is the most dangerous subset of the campaign: users who knew enough to search for a specific, reputable VPN provider were still at risk of installing a malicious impersonator.

The Chrome Web Store's extension review process doesn't verify that an extension actually is what it claims to be. A developer account can publish an extension called "NordVPN - Free" with a similar icon and description, and it will appear in search results alongside or even above the legitimate product until it's reported and removed.

This impersonation approach also exploits the trust signal users associate with finding something in an official app store. Chrome Web Store, Apple App Store, and Google Play all have review processes — but none of them provide complete protection against impersonation. The 737 extensions accumulated 75,486 installs before being identified, which means tens of thousands of users believed they had installed a real product.

How to Audit Your Chrome Extensions Right Now

If you have any free VPN or proxy extension installed in Chrome, you should check it immediately:

  1. Open Chrome and go to chrome://extensions
  2. Look for any extensions with "VPN," "proxy," "unblocker," or "privacy" in the name
  3. For each one: click "Details" and check the publisher — is the publisher the company you expected? Does the developer account have a history of legitimate products?
  4. Check the extension's permissions — a VPN extension that requests access to "read and change all your data on the websites you visit" has full access to everything you do in your browser
  5. If you're uncertain, remove it

The legitimate version of any major VPN provider's Chrome extension will be published by that provider's verified developer account, typically linked from the provider's official website. If the extension you have installed came from a different developer account — even if the name and icon look right — it's a risk.

What a Real VPN Extension vs. a Proxy Extension Actually Does

Not all browser extensions claiming to be VPNs work the same way. Understanding the difference:

Proxy extension: Routes browser traffic through a remote server operated by the extension developer (or a third party). The traffic may or may not be encrypted. The proxy operator can see what sites you visit. These are often free because the operator monetizes your traffic data. The 737 removed extensions were proxy extensions.

Companion browser extension for a real VPN: Some legitimate VPN providers publish Chrome extensions that control or configure their system-level VPN app installed on your computer. These extensions don't route traffic themselves — they communicate with the real VPN app running at the OS level. If you remove the VPN app, the extension doesn't provide any protection on its own.

DNS-over-HTTPS extension: Some extensions only change how DNS lookups are processed in the browser — not a VPN at all, despite sometimes being marketed as privacy tools.

The only extension that provides meaningful traffic protection is one that acts as a companion to a real, system-level VPN app. A standalone extension that claims to provide full VPN protection without any separate application installed is, by definition, not doing what a real VPN does.

Why "Free" VPN Extensions Are Almost Always a Bad Tradeoff

Operating real VPN infrastructure — servers, bandwidth, encryption at scale — costs real money. Free VPN products that don't charge users have to generate revenue somewhere. The three most common models:

  • Selling traffic data — logging which sites users visit and selling that data to advertising or analytics companies. This is the opposite of privacy.
  • Injecting ads — inserting advertising content into the pages users visit, often in a way that's difficult to detect.
  • Reselling bandwidth — using users' internet connections as exit nodes for other traffic, effectively making users unwitting participants in a proxy network. This can expose users to liability for traffic that passes through their connection.

The 737 extensions identified this week were using the proxy network model. Users' traffic was routed through infrastructure operated by a third party — not for the users' benefit, but for the infrastructure operator's.

What Google Has Done and What It Hasn't

Google removed the identified extensions from the Chrome Web Store after researchers disclosed the campaign. However, extensions already installed on users' devices are not automatically removed — each user must remove them manually. Users who installed any of the 737 extensions before they were removed still have them active unless they've cleared their extensions manually.

Google's Chrome Web Store review process does catch many malicious extensions before they're published, but it is not comprehensive. The 40 developer accounts that published these 737 extensions passed whatever review process existed at submission time. The campaign was identified by external researchers monitoring extension behavior in production, not by Google's pre-publication review.

What to Do If You've Been Using a Fake VPN Extension

  • Remove it immediately — go to chrome://extensions and remove any VPN or proxy extension you didn't install from the official website of a known provider
  • Change passwords for sites you accessed while using it — if the extension routed your traffic through a proxy, those sessions may have been monitored
  • Check for any unusual account activity — email, banking, work accounts accessed while the extension was active
  • Run a breach check — verify your email addresses against known breach databases at cyberfenceplatform.com/tools/breach-check
  • Install a real VPN app — not a browser extension, but a system-level application that encrypts all traffic from all apps on your device

The 737-extension campaign is a concrete illustration of the problem with free browser-based "VPNs": they're often not VPNs at all, and when they are routing your traffic, you have no reliable way to know what's being done with it. A system-level VPN with a transparent privacy policy, a documented zero-log practice, and a known operator is not just a better product — it's the only type of product that actually does what users think they're installing when they search for a VPN.

Replace Your Browser Extension With a Real VPN

CyberFence is a real VPN app — not a browser extension. Download it from the App Store or Google Play. AES-256-GCM encryption for all apps on your device, Web Shield DNS filtering, zero logs, US-operated. Start your free trial.

View Plans →

Want to go deeper? Read the CyberFence competitor comparison hub , our free privacy and security tools , or CyberFence plans and pricing .