FINDING · DEPLOYMENT

Malicious VPN browser extensions using chrome.proxy.settings route all browser requests through an operator-controlled SOCKS5 proxy, giving that operator direct visibility into source IP, connection destinations, TLS SNI hints, and cleartext HTTP content. For HTTPS destinations the payload is not readable, but connection metadata, access patterns, and DNS queries remain exposed at the proxy layer regardless of in-tunnel encryption.

From 2026-anon-vpn-ai-deepseek免费 VPN 扩展接管流量,AI 推理日志泄密:DeepSeek Harness、平台审计与数学进展周报 | 二毛 · §免费VPN扩展的核心问题 · 2026 · ermao.net (Chinese-language circumvention blog)

Implications

Tags

censors
generic
techniques
sni-blockingtraffic-shape
defenses
shadowsocksech-esni

Extracted by claude-sonnet-4-6 — review before relying.