BrowsecVPN
nmcnfhmlonpkabmmoepefcokljhelkoe
Risk Score
4.94
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: claims to provide VPN for Instagram/Telegram/YouTube with gmail-only developer identity and no business presence.
- Privacy policy is Google's own policy — not scoped to this extension, admits data collection and third-party sharing.
- Developer is anonymous (no name, free-webmail gmail address, no developer domain), no verified publisher status.
- proxy permission gives full traffic routing control; extremely dangerous if extension is malicious or transferred.
- Only 27 installs with a HIGH-tier permission (proxy) — classic tail-attack-surface / sleeper pattern.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands mentioned: Instagram, Telegram, YouTube; developer domain is gmail.com, confirmed_owner=false.
- anonymous_developer store developer_name is empty; email aofnoyaofnoy99@gmail.com is free-webmail; no business website; no verified publisher.
- generic_privacy_policy store Privacy URL is Google Account policy (scope_extension=false, data_collection=true, third_party_sharing=true). Scores +10 privacy pillar.
- small_install_high_perm api install_perm_anomaly: 27 installs + proxy permission flagged small_install_high_perm=true.
- proxy_permission manifest proxy declared; allows rerouting all browser traffic through attacker-controlled endpoints.
- free_webmail_dev store Developer email aofnoyaofnoy99@gmail.com; no developer name; floor reputation >=7.5 per rubric.
- no_cve_no_bad_hosts api cve_findings_raw empty; bad_host_hits empty; js_external_hosts empty. No direct malware signal detected.
- mv3_no_csp_declared manifest MV3 has strict CSP defaults; csp_present=false is expected and no v2 network penalty applied.
Permissions Breakdown
- proxy high Allows full control of browser network routing — core VPN risk but highly abusable.
- storage low Local key-value store; minimal risk in isolation.
Pillar Scores
Permissions4.00
Reputation9.00
Network0.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:20
Listing SHA
c0fb7380da11…
Force block
— not fired
Score recovered
no
Elapsed
—