Back to articles

Proton VPN extension review: security score, privacy analysis & safer alternatives

The real Proton VPN extension is a standalone browser VPN — with broad permissions by design. Here's what it actually requests and how to spot the fakes.

Maxim Kosterin
11 min read

TL;DR

  • The official Proton VPN extension from Proton AG is a standalone browser VPN — it protects your in-browser traffic on its own, no desktop app required, and it's free
  • Because it's a real VPN, it requests broad permissions — access to all URLs plus proxy, tabs, and webRequest. That's a high-capability footprint, but it matches the job
  • According to Proton's own advisory, fake Proton VPN extensions passed Google's Chrome Web Store review and stayed live for weeks in 2026 — and the fakes request the same broad permissions, so the permission list alone won't tell them apart
  • The only reliable check: install from proton.me, confirm the publisher is "Proton AG," and match the extension ID

You trust Proton because they built their reputation on privacy. Encrypted email, zero-knowledge storage, and a VPN that gets independently audited. So when someone searches "Proton VPN" in the Chrome Web Store and finds a result with decent reviews, they assume they're getting the real thing.

That assumption is getting people burned.

In early 2026, Proton went public with a disclosure that should make anyone who installs VPN extensions nervous: fake extensions impersonating their VPN service had been repeatedly approved through Google's review process.

According to Proton's own security advisory, they reported these impostors to Google at least three times since January 2026 — and in multiple cases, removal still took several weeks. Proton described the signs of impersonation as "blatantly obvious," yet the fakes kept getting through.

I want to break down what's actually happening here: what the real Proton VPN extension does, what it can genuinely see inside your browser, and — most importantly — how to check that what you installed is the real thing.

What the official Proton VPN extension actually does

Here's the first thing to get right, because plenty of write-ups (including an earlier version of this one) got it wrong: the Proton VPN browser extension is a standalone VPN, not a remote control for the desktop app.

Per Proton's own documentation, the extension is a stand-alone product that "protects exclusively traffic inside your browser," and it's available to everyone with a Proton account — including the free tier. You do not need the desktop app installed for it to work. Install it on its own and it will route your browser's traffic through Proton's servers by itself.

The trade-off is scope, not capability. Proton's full VPN apps protect all the traffic leaving your device; the extension protects only your browser's traffic. Everything outside the browser keeps using your normal connection. For a lot of people that's exactly what they want — browser privacy without slowing down every other app on the system.

And it's a real VPN, not a stripped-down toy. The extension supports Secure Core (routing your connection through a hardened multi-hop server chain), split tunneling, auto-connect, and per-site rules. It's audited by third-party security professionals, which is more than most browser extensions can say.

Security analysis: permissions, access, and risks

Now the part that matters for a security review — and where the honest answer surprises people.

Because the extension routes your browser traffic, it needs to see and redirect that traffic. So its permission footprint is broad, not slim. As of mid-2026, the official Manifest V3 extension (published by Proton AG, around 2 million users) declares:

  • Host access to every sitehttps://*/, http://*/, and even ftp://, ws://, and wss://. That's the equivalent of <all_urls>
  • proxy — the API that actually reroutes your browser traffic through the VPN server
  • tabs — to know which tab is active and apply per-site rules
  • webRequest and webRequestAuthProvider — to observe and authenticate requests as they're proxied
  • privacy, scripting, storage, idle, notifications — connection state, UI, and browser privacy settings

Third-party trackers like chrome-stats classify this as high risk impact, low risk likelihood — and that combination is the whole point. "High impact" means the extension can touch a lot: it sees every request your browser makes. "Low likelihood" means the odds of it turning malicious are low, because of who publishes it and how long it's had a clean track record.

This is the mental model I keep coming back to on this blog: a permission is only a red flag when it doesn't match the job. A wallpaper switcher asking for all-URLs access is alarming. A VPN asking for all-URLs access is doing exactly what a VPN has to do — you literally cannot route browser traffic you're not allowed to see.

So the permissions aren't the problem here. The publisher is what you're trusting.

Privacy score breakdown

So the extension isn't "clean because it asks for little." It asks for a lot. It scores well because of everything around the permissions: Proton AG is a known Swiss entity with a public no-logs policy, an independently audited codebase, a multi-year track record, and millions of users. That's the basis for trusting a tool with this much reach into your browsing.

Flip every one of those factors and you get the actual threat. A brand-new extension you've never heard of, requesting all-URLs host access plus proxy and webRequest, with no audit and no track record — that's the same capability footprint pointed at you by someone you have no reason to trust.

Which is precisely what the 2026 impersonation wave delivered.

The 2026 impersonation crisis on the Chrome Web Store

According to Proton's public security advisory and reporting by TechRadar, fake Proton VPN extensions passed Chrome Web Store review and remained available for several weeks despite Proton reporting them multiple times starting in January 2026.

The malicious extensions were designed to steal login credentials, harvest personal data, and monitor browsing activity. TechRadar's coverage noted that some of the fakes specifically targeted Russian-speaking markets — regions where VPN demand is high due to content restrictions, and where users may be searching for alternatives in the Chrome Web Store rather than going directly to a VPN provider's website.

What makes this case notable isn't the attackers' sophistication. Brand impersonation is old. What's notable is that Proton — the impersonated party — couldn't get fakes removed in a timely way despite having a direct line to report abuse. As of publication in March 2026, Google had not publicly responded to Proton's specific concerns about the removal timeline.

Here's the sharp part, and it ties straight back to the permission analysis above: a fake VPN extension requests the same broad permissions as the real one. All-URLs access, proxy, webRequest — a genuine VPN needs every one of them, so a fake can request all of them without looking out of place. You can't spot the impostor by reading its permission list. Impersonators aren't the only VPN-extension risk, either — even extensions published under a real brand have been caught overreaching, like the case where Urban VPN's extension was reported harvesting AI-chat data from millions of users.

That's why verification has to happen at the identity layer, not the permission layer.

How to verify you have the real Proton VPN extension

Five steps, in order of importance:

1. Install from proton.me, not from a search. Proton's own advice: "Download software only from Proton's official website, proton.me, rather than searching directly within extension or app stores." Start at their website and click through to the extension from there.

2. Check the publisher name. On the Chrome Web Store listing, look for "Proton AG" under "Offered by." Not "ProtonVPN" as a single word, not a variation with numbers. The full legal name, registered in Switzerland.

3. Check the extension ID. The official Chrome extension ID is jplgfhpmjnbigmhklmmbgecoobifkmpa. You can see the ID at chrome://extensions with developer mode enabled. If the ID doesn't match the one linked from proton.me, you have a different extension — remove it.

4. Sanity-check the install base. The real extension has millions of users and years of reviews. A "Proton VPN" listing with a few hundred users and a recent publish date is a red flag, no matter how polished the icon looks.

5. Look it up before installing. Check the extension at catalog.extenshi.io by searching the name or entering the ID directly. The catalog shows the permission profile, publisher, and user counts side by side, so you can confirm the listing matches the official one — and flag anything that doesn't.

Alternatives worth considering

If all this is making you question whether you want a VPN browser extension at all — a fair question I weighed in my Firefox built-in VPN vs. VPN extensions comparison — here are three legitimate approaches worth knowing:

Proton VPN desktop app — If you want every app on your device covered, not just the browser, the desktop app is the answer. It routes all system traffic through the VPN. More protection, more surface area; the browser extension is the lighter-touch option when you only care about browsing.

Windscribe browser extension — Windscribe is another provider offering a genuine standalone browser extension. Like Proton's, it needs broad host access because it routes traffic through a browser proxy — that's inherent to the category, not a Windscribe quirk. It has a clear privacy policy and has been independently reviewed. You can see the full permission breakdown at catalog.extenshi.io before committing.

Mullvad Browser — Mullvad's approach sidesteps the extension question entirely. They ship a hardened Firefox-based browser with built-in tracking protection, which you pair with the Mullvad VPN desktop app. Overkill for casual users, genuinely solid for anyone who needs strong privacy guarantees — and there's nothing to fake or impersonate.

Final recommendation

The official Proton VPN extension earns a clean bill of health — but not because it asks for little. It asks for a lot, exactly as much as a browser VPN needs, and it earns trust through a known publisher, a third-party audit, and a long track record. If you installed it from proton.me and confirmed the publisher is Proton AG with extension ID jplgfhpmjnbigmhklmmbgecoobifkmpa, you're in good shape.

The real problem is the impersonation ecosystem around it. VPN extensions are high-value targets because users actively search for them and extend trust to the category by default — and because a fake can request the same permissions as the real thing without standing out. The Chrome Web Store's moderation proved it couldn't keep up with Proton impersonators in 2026, even when the real Proton company was actively filing reports.

My take: if you already use Proton VPN, verify your extension now using the publisher-and-ID check above. If you're evaluating VPN extensions, start at the provider's official website — never from a store search — and confirm the identity before granting permissions. The permissions will look broad either way. What separates the real tool from the trap is who's behind it.

Any extension you're unsure about, run it through the catalog first. See the full security report for Proton VPN →

FAQ

Is the Proton VPN extension safe?

The official one from Proton AG (extension ID jplgfhpmjnbigmhklmmbgecoobifkmpa) is trustworthy — it's audited, no-logs, and backed by a known Swiss publisher. It does request broad permissions (all-URLs access, proxy, webRequest), but a VPN needs those to route your traffic. The real danger is impersonators: fake "Proton VPN" extensions passed Chrome Web Store review in 2026 and request the same permissions. Verify the publisher and ID before trusting any listing.

Do I need the Proton VPN app to use the extension?

No. The browser extension is a standalone product — it protects your in-browser traffic on its own, on Chrome or Firefox, and it's available even on the free plan. The desktop app is a separate option for when you want all your device's traffic protected, not just the browser's.

Why does the Proton VPN extension ask for access to all my sites?

Because it's a VPN. To route your browser traffic through a secure server, it has to be able to see and redirect requests to every site — that's what the all-URLs host access and the proxy permission are for. Broad permissions are expected here; what matters is trusting the publisher behind them.


This article is based on publicly available security research and news reporting. Extenshi does not independently verify all claims made by third-party researchers. References to specific companies or products reflect the findings of cited sources and do not constitute accusations of intentional wrongdoing. If you believe any information is inaccurate, please contact us at [email protected].

Related Articles