Free VPN for Chrome - freemybrowser
bibmocmlcdhadgblaekimealfcnafgfn
Risk Score
5.53
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension — worst-case privacy score.
- proxy + cookies + https://*/* combo: extension can intercept and read all HTTPS cookies across every site visited.
- No developer name listed; missing organizational accountability for a high-capability VPN extension.
- Extension contacts facebook.com externally — unexpected third-party JS host for a VPN with broad cookie access.
- 15 months since last update; stale for a security-critical extension handling all user traffic.
Evidence
- privacy_policy_admits_data_and_sharing_not_scoped api Policy fetched: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5 rule D).
- proxy+cookies+broad_host manifest proxy, cookies, declarativeNetRequestWithHostAccess, webRequest all declared with https://*/* → high-capability cluster.
- no_developer_name store developer_name is empty string; verified_publisher present but no named org; reputation +1.0.
- facebook_external_host crx js_external_hosts includes facebook.com — unexpected for a VPN; potential tracking/analytics dependency.
- install_url_hijack crx install_url_hijack=true targeting settings.html (internal); minor signal, no third-party redirect.
- months_since_update_15 store 15 months since last update → maintenance +6.0 (6-12 bracket exceeded; 12-24 = +6.0).
- dom_sink_innerhtml_userctrl crx popup.100f6462.js: innerHTML from variable; no CSP present → +2.0 code quality (FIX B applies: csp_present=false).
- verified_publisher_featured store Both verified_publisher and is_featured_by_google true; reputation -3.0 -2.0; but CAPABILITY GATE applies (proxy/webRequest/cookies) → cap discount at -1.0 per 0c (monetization not present but stale >18mo? No, 15mo; cve empty, domain resolves → full discount applies minus gate).
Permissions Breakdown
- tabs medium Access to tab URLs and metadata; standard for VPN routing decisions.
- webRequest high Intercepts all network requests; core to VPN but high-impact capability.
- proxy high Routes all browser traffic; highest-risk permission for a VPN extension.
- unlimitedStorage low Local storage quota removal; low direct risk.
- declarativeNetRequestWithHostAccess high Can block/redirect requests across all HTTPS hosts.
- background low Persistent background processing; expected for VPN.
- webNavigation medium Observes navigation events across all tabs.
- cookies high Read/write cookies site-wide; paired with broad host access multiplies risk.
- storage low Local extension storage; standard.
- webRequestAuthProvider medium Can supply authentication credentials to network requests.
- https://*/* high Broad host access over all HTTPS sites; amplifies cookies+proxy risk.
Pillar Scores
Permissions7.50
Reputation3.50
Network4.50
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:51
Listing SHA
23d1e39bf6ca…
Force block
— not fired
Score recovered
no
Elapsed
—