Saturday, April 5, 2025
HomeSecurity News70% Of Chrome VPN Extensions Leak Your DNS Requests

70% Of Chrome VPN Extensions Leak Your DNS Requests

Published on

SIEM as a Service

Follow Us on Google News

Popular chrome VPN Extensions leak customers DNS requests that made through Google Chrome DNS Prefetching feature which use to resolve the domains names before the user follows the link.

DNS Prefetching is to reduce the latency delays that improves the website leading speed in chrome by pre-resolving the domains of those websites.

For VPN browser extensions chrome provides the proxy connection in two modes fixed_servers and pac_script. With fixed_servers it specifies the SOCKS proxy server and all the connections will be routed through the same proxy server.

pac_script is the dynamically changing one under various conditions and a majority of the VPN provides using the majority of VPN extensions use the mode pac_script.

John Mason from best VPN says Now, the issue is that DNS Prefetching continues to function when the pac_script mode is used. Since HTTPS proxy does not support proxying DNS requests and Chrome does not support DNS over SOCKS protocol, all prefetched DNS requests will go through the system DNS. This essentially introduces DNS leak.

He conducted the survey against 15 VPN and 10 VPNs are vulnerable to the data leak.

VPN Extensions Leak DNS Requests

Hola VPN
OpenVPN
TunnelBear
HotSpot Shield
Betterment
PureVPN
VPN Unlimited
ZenMate VPN
Ivacy VPN
DotVPN

VPN Extensions Not Affected

WindScribe
NordVPN
CyberGhost
Private Internet Access
Avira Phantom VPN

How to test you VPN Extensions Leak DNS Requests

To test the VPN leaks the DNS request

Activate the Chrome plugin of your VPN
Go to chrome://net-internals/#dns
Click on “clear host cache”
Go to any website to confirm this vulnerability

How to Mitigate VPN Extensions Leak DNS Requests

John Mason provided mitigations for Users who want to protect themselves.

1. Navigate to chrome://settings/ in the address bar
2. Type “predict” in “Search settings”
3. Disable the option “Use a prediction service to help complete searches and URLs typed in the address bar” and “Use a prediction service to load pages more quickly”

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti...

Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware

A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing...

EncryptHub Ransomware Uncovered Through ChatGPT Use and OPSEC Failures

EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of...

PoisonSeed Targets CRM and Bulk Email Providers in New Supply Chain Phishing Attack

A sophisticated phishing campaign, dubbed "PoisonSeed," has been identified targeting customer relationship management (CRM)...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Advanced CoffeeLoader Malware Evades Security to Deliver Rhadamanthys Shellcode

Security researchers at Zscaler ThreatLabz have identified a new sophisticated malware family called CoffeeLoader,...

Clio: Real-Time Logging Tool with Locking, User Authentication, and Audit Trails

Clio is a cutting-edge, secure logging platform designed specifically for red team operations and...

Enhancing Satellite Security by Encrypting Video Data Directly on Payloads

The rapid expansion of low-Earth orbit (LEO) satellite constellations has underscored the need for...