News: 1755775717

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google yet to take down 'screenshot-grabbing' Chrome VPN extension

(2025/08/21)


Security boffins at Koi Security have warned of a shift in behavior of a popular Chrome VPN extension, FreeVPN.One, which recently appears to have begun snaffling screenshots of users' page activity and transmitting them to a remote server without their knowledge – and Google has yet to take it down.

"FreeVPN.One shows how a privacy branding can be flipped into a trap," Koi's Lotan Sery writes in the company's [1]research report . "They've earned verified status and even featured placement on the Chrome Web Store. And while Chrome claims to perform security checks on new versions of extensions, using automated scans, human reviews, and monitoring for malicious code or behavior changes — the reality is that these safeguards failed. This case shows that even with those protections in place, dangerous extensions can slip through, highlighting serious gaps in security across major browser marketplaces."

The report into the FreeVPN.One extension comes amid a [2]surge of interest in VPNs following the introduction of the UK's Online Safety Act. The Act requires certain websites – though not necessarily just the ones you're thinking of – to [3]verify the age of their visitors . If Children's Commissioner Dame Rachel de Souza [4]has her way , however, at least kids won't fall foul of malicious VPNs.

[5]

Koi's research found that the extension, which had more than 100,000 verified installations at the time of publication, is silently capturing screenshots a little over a second after each page load before transmitting them to a remote server – initially in the clear, then in a later update obfuscated with encryption. The behavior, the researchers claim, was introduced in July – after laying the groundwork with smaller updates which requested additional permissions to access all sites and inject custom scripts.

[6]

[7]

The Register reached out to the developer of FreeVPN.one, who insisted that FreeVPN.one's Chrome extension "is fully compliant with Chrome Web Store policies, and any screenshot functionality is disclosed in our privacy policy," sending us a link to the page [8]here . They added: "All data collected is encrypted and handled according to standard practices for browser extensions. We are committed to transparency and user privacy and welcome readers to review our documentation for further details."

The dev offered Koi's researchers a range of excuses including that screenshots would only trigger "if a domain appears suspicious" as part of a "background scanning" feature. The researchers refuted this with evidence of activation on well-trusted domains including Google's own, and that screenshots "are not being stored or used" but "only analyzed briefly for potential threats" – which sounds very much like a use to us.

[9]

As to how such behavior made its way into the Chrome Web Store, which includes a get-out clause in its terms of service stating that "You agree that Google is not responsible for any Product on the Web Store that originates from a source other than Google," the secret appears to lie in patience. The extension has been around for years, and appears to have been doing exactly what it promised for most of that time – only appearing to switch to sneakily exfiltrating screenshots more recently.

[10]The UK Online Safety Act is about censorship, not safety

[11]UK proxy traffic surges as users consider VPN alternatives amid Online Safety Act

[12]$380M lawsuit claims intruder got Clorox's passwords from Cognizant simply by asking

[13]You have a fake North Korean IT worker problem – here's how to stop it

That shift would seem to make it eligible for removal from the Chrome Web Store: a developer declaration states that users' data is "not being used or transferred for purposes that are unrelated to the item's core functionality." Hidden below the fold in the product overview, however, is mention of "advanced AI Threat Detection" with a "passive mode" to which is "constantly monitoring the websites you are viewing and scanning them visually if you visit a suspicious page" - matching the developer's claims as to the reason for taking screenshots, but without stating that "scanning them visually" means "sending pictures of everything you do to a remote server without notification or any way to opt out."

The Register reached out to Google to ask whether it was investigating Koi's report on the extension, and whether it intends to de-list it while it does so; the company had not replied at the time of publication, but The Reg notes that the extension remained active and available for download at the time of publication. ®

Get our [14]Tech Resources



[1] https://www.koi.security/blog/spyvpn-the-vpn-that-secretly-captures-your-screen

[2] https://www.theregister.com/2025/07/28/uk_vpn_demand_soars/

[3] https://www.theregister.com/2025/08/04/millions_of_age_checks_performed/

[4] https://www.theregister.com/2025/08/19/uk_commissioner_suggests_govt_stop/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aKdCmdyrcYQB0dTHxTf6SQAAAIE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aKdCmdyrcYQB0dTHxTf6SQAAAIE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aKdCmdyrcYQB0dTHxTf6SQAAAIE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.freevpn.one/privacy.html

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aKdCmdyrcYQB0dTHxTf6SQAAAIE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2025/08/21/the_uk_online_safety_act/

[11] https://www.theregister.com/2025/08/08/proxy_usage_jumps_in_uk/

[12] https://www.theregister.com/2025/07/23/lawsuit_clorox_vs_cognizant/

[13] https://www.theregister.com/2025/07/13/fake_it_worker_problem/

[14] https://whitepapers.theregister.com/



Great

Anonymous Coward

All ready for when British kids start using free VPNs - cos they're not old enough for credit cards

Big Brother is always watching

ComicalEngineer

It seems that George Orwell was just about 30 years too early in his time estimate.

Re: Big Brother is always watching

seldom

41 actually

Re: Big Brother is always watching

cookieMonster

Pedantic. I approve :-)

I'll have another one, please

Snake

"FreeVPN.one's Chrome extension "is fully compliant with Chrome Web Store policies, and any screenshot functionality is disclosed in our privacy policy"

FreeVPN: Your beating will continue until you stop believing that they will...stop.

Carry on, nothing new here. We have all received the [governmental / private] systems that the autocracy has fully paid for.

In caring for others and serving heaven,
There is nothing like using restraint.
Restraint begins with giving up one's own ideas.
This depends on Virtue gathered in the past.
If there is a good store of Virtue, then nothing is impossible.
If nothing is impossible, then there are no limits.
If a man knows no limits, then he is fit to be a ruler.
The mother principle of ruling holds good for a long time.
This is called having deep roots and a firm foundation,
The Tao of long life and eternal vision.