Trusted Chrome VPN Extension Exposed as Spyware

Trusted Chrome VPN Extension Exposed as Spyware

Arkadiy Andrienko

A popular free Chrome extension called FreeVPN.One, which was marketed as a privacy tool, has been exposed as a front for mass data collection. As uncovered by cybersecurity researchers, the app was secretly taking full screenshots of every open browser tab and sending them to third-party servers.

The spy mechanism built into the extension activated automatically upon visiting any website. This happened completely without the user's knowledge, with no notifications or permission prompts. The screenshots captured absolutely everything: private messenger chats, online banking details, personal photos, and other sensitive materials.

Analysis revealed the extension used an internal Chrome API to hijack the data. The screenshots were then packaged with metadata, including links to visited pages and user identifiers. This entire trove of information was transmitted encrypted to a remote server. Researchers were particularly alarmed that the data harvesting began before any user interaction with the extension's advertised "threat scan" feature.

When confronted, FreeVPN.One's developer insisted the screenshot function was part of a security system designed for AI threat analysis. However, they provided zero proof that the collected data wasn't being stored. After their initial responses, the creator ceased all communication with users.

Users who installed this extension are strongly advised to remove it immediately. It would also be prudent to change passwords for any important services that were accessed in the browser while the extension was active. For real privacy, experts recommend choosing reputable VPN services with transparent data policies and a history of independent security audits.

    About the author
    Comments0