CRX aminer
Extension icon

AdGuard VPN: free & secure proxy

Version 2.9.8 View in Chrome Web Store

Last scanned: about 14 hours ago

Extension Details

Developer: Adguard Software Limited
Rating: 4.1 ★ (3.4K ratings)
Users: 500,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

AdGuard is a well-established cybersecurity company with a solid reputation in the ad-blocking and privacy space. The extension has 500,000 users and a decent 4.1-star rating from 3,400+ reviews, indicating reasonable user satisfaction. The company has been operating for years and is known for legitimate privacy tools.

Concerns:

The extension's permission set is extremely broad and powerful, even for a VPN service. The management permission allowing control over other extensions is particularly concerning and unnecessary for VPN functionality. The combination of proxy control, web request interception, privacy settings modification, and unlimited data storage creates a perfect storm for potential abuse. The all_urls host permissions and content script injection capabilities mean this extension has complete access to every website you visit and can modify any web content.

While these permissions may be technically necessary for VPN functionality, they create significant attack surface if the extension were compromised or if the company's practices changed. The ability to intercept all web traffic, modify privacy settings, and manage other extensions goes beyond typical VPN requirements.

Recommendations:

Given the critical risk level, run this extension in a completely separate Chrome profile dedicated only to VPN usage. Never use this profile for sensitive activities like banking or work. Consider using a standalone VPN application instead of a browser extension for better security isolation. Regularly review the extension's behavior and immediately remove it if you notice any suspicious activity.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: management
This extension has the management permission. Can manage other extensions. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: privacy
This extension has the privacy permission. Can modify privacy settings. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: proxy
This extension has the proxy permission. Can control proxy settings. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.