CRX aminer
Extension icon

SetupVPN - Lifetime Free VPN

Version 4.0.9 View in Chrome Web Store

Last scanned: about 11 hours ago

Extension Details

Developer: SetupVPN Inc
Rating: 4.7 ★ (47.4K ratings)
Users: 1,000,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has strong user adoption metrics with 1 million users and a high 4.7-star rating from 47,400 reviews, suggesting legitimate functionality. SetupVPN Inc appears to be an established company in the VPN space. The high user base and positive ratings indicate the extension generally works as advertised for VPN services.

Concerns:

The permission set is extremely broad and powerful for a VPN extension. The combination of proxy, webRequest, and all_urls permissions creates a perfect storm for potential data interception. The management permission is particularly concerning as it allows control over other extensions, which is unnecessary for VPN functionality. The unsafe WebAssembly execution policy could hide malicious code or enable resource-intensive operations. The tabs permission provides unnecessary access to browsing behavior across all websites.

While VPN extensions legitimately need some elevated permissions to function, this extension's permission scope exceeds what's typically required. The ability to intercept all web traffic, manage other extensions, and execute potentially unsafe code creates significant attack vectors if the extension were compromised or malicious.

Recommendations:

Run this extension in a completely separate Chrome profile to isolate it from your main browsing activities and other extensions. Consider using a dedicated VPN application instead of a browser extension for better security isolation. If you must use this extension, regularly audit your other installed extensions since it has management permissions over them.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: management
This extension has the management permission. Can manage other extensions. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: proxy
This extension has the proxy permission. Can control proxy settings. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.