Browsec VPN - Free VPN for Chrome
omghfjlpggmjjaagoclmmobgdodcjboh
Risk Score
4.73
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 — arbitrary code execution; unfixed (need >=1.12.1).
- CSP connect-src lists 80+ low-reputation HTTP CDN domains (cacheflow, fastfetch, datafrenzy, etc.) — anomalous for a VPN.
- Privacy policy fetched but scope_extension==false and data_collection==true — policy does not specify what THIS extension collects.
- proxy+webRequest+scripting+browsingData+<all_urls> is maximum traffic-interception capability; expected for VPN but very high blast radius.
- uninstall_url_hijack == true — extension registers an uninstall redirect URL.
Evidence
- critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (ACE, critical) and CVE-2026-27601 (DoS, high); fixed_in 1.13.8.
- csp_connect_src_excessive_domains crx connect-src whitelists 80+ opaque HTTP CDN domains (cacheflow.cloud, datafrenzy.org, fastfetch.xyz, etc.).
- privacy_policy_not_scoped store Policy fetched; data_collection=true, scope_extension=false — does not disclose what this extension collects.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() called on uninstall; target URL not resolved.
- function_constructor_multiple_files crx new Function() used in 6 page scripts; snippet suggests library polyfill pattern but still a code-quality risk.
- verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; 8M installs, rating 4.5 — strong positive trust signals.
- high_permissions_vp_category_discount manifest VPN category justifies proxy+webRequest+browsingData+<all_urls>; -1.5 justified-broad-permission discount applied.
- js_external_hosts_9_domains crx 9 external JS hosts including gist.githubusercontent.com, gh-proxy.com, www.google-analytics.com.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- proxy high Full proxy control — can reroute all browser traffic through any server.
- webRequest high Intercepts all HTTP requests; combined with proxy and <all_urls> is maximum-reach.
- browsingData high Can delete history, cookies, cache across all sites.
- scripting high Programmatic script injection into any page given <all_urls> host permission.
- declarativeNetRequest medium Can block/redirect network requests declaratively.
- webRequestAuthProvider medium Provides credentials for proxy auth challenges — sensitive credential surface.
- storage low Local key-value store; low risk in isolation.
- alarms low Scheduling only; minimal risk.
- background low Persistent background service worker; expected for VPN.
- <all_urls> high Broad host access amplifies proxy+scripting+webRequest to cover every site visited.
Pillar Scores
Permissions6.50
Reputation2.00
Network5.50
Webstore3.00
Maintenance0.00
Privacy9.00
Code Quality2.50
CVE Exposure7.00
Scoring History
| sssieddrubricxsx | 5.14 | Medium | review | 2026-08-10 |
| v3.6 | 4.73 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA
328c8a28b089…
Force block
— not fired
Score recovered
no
Elapsed
34.3s