737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

A recent investigation has uncovered a shocking number of Chrome VPN extensions that are secretly routing user traffic through proxies, potentially exposing sensitive data and compromising online security. The affected extensions, totaling 737, have been installed by millions of users worldwide, making this a significant threat to internet safety.

These VPN extensions, designed to protect users’ browsing activities from prying eyes, have instead been used as backdoors for malicious actors to intercept and manipulate user traffic. By routing traffic through proxies, these extensions create an opportunity for hackers to eavesdrop on sensitive information, inject malware into websites, or even steal login credentials. This type of exploit is known as a “man-in-the-middle” (MitM) attack.

The investigation revealed that many of the affected extensions were created by reputable companies, but their developers had either knowingly or unknowingly implemented proxy routing functionality without informing users. This raises concerns about the vetting process for Chrome extension developers and the lack of transparency in the way these extensions operate. In some cases, it appears that developers have used third-party services to manage their extensions’ traffic, creating a layer of complexity that makes it difficult for users to understand what is happening with their data.

The implications of this discovery are far-reaching. Not only do these proxy-routed VPN extensions put individual users at risk, but they also compromise the security of organizations and businesses that rely on employees using these extensions while accessing company networks or sensitive information online. As a result, it’s essential for both individuals and enterprises to review their Chrome extension usage and ensure that they are not inadvertently exposing themselves to potential threats.

To mitigate this risk, users should first check if any of the affected VPN extensions are installed on their browsers by reviewing their Chrome extension list. If an extension is found, it’s crucial to remove it immediately and consider alternative VPN solutions that prioritize transparency and security. Additionally, organizations should educate their employees about the importance of carefully evaluating Chrome extensions before installing them and ensure that company-approved extensions meet stringent security standards.

Ultimately, this incident serves as a stark reminder of the need for vigilance in the face of rapidly evolving cybersecurity threats. By staying informed and taking proactive steps to protect our online activities, we can minimize the risk of falling victim to these types of attacks and maintain a safer digital environment.


Source: The Hacker News — 2026-08-12