Security researchers have identified critical vulnerabilities in popular VPN services that could leak users' real IPs , as well as other sensitive data
VPN services are a great way to protect your daily online activities, as they encrypt your data , enhance your overall security, and hide your real IP address . But what happens when your VPN , which is supposed to protect your privacy , actually leaks your sensitive data and your real location?
A group of ethical hackers has revealed that three popular VPN service providers – HotSpot Shield , PureVPN and Zenmate – with millions of customers worldwide, are vulnerable to vulnerabilities that could compromise users' privacy
For those who don't know, PureVPN is the same company that, while boasting about its "no-log" policy, a few months ago helped the FBI arrest a man involved in a cyber espionage case.
After a series of security checks on the above VPN, the VPN Mentor found that all three leak the real IP of their users, and these can then be used to identify their real location.
What does this mean for end users? As VPN Mentor explains, thesevulnerabilities could “allow governments, hostile organizations, or individuals to determine a user’s real IP , even when using a VPN.”
The vulnerabilities in ZenMate and PureVPN have not been disclosed for security reasons, as they have not been patched at this time, while VPN Mentor reports that the security issues found in ZenMate VPN were less significant than those in HotSpot Shield and PureVPN.
The team discovered three vulnerabilities in AnchorFree 's HotSpot Shield , ( CVE -2018-7879, CVE -2018-7878, CVE -2018-7880) which have been patched by the company.
It should be noted here that all three vulnerabilities were found in HotSpot Shield 's free Chrome plugin , and not in the desktop/ smartphone applications .
Researchers have reported similar vulnerabilities in the Zenmate and PureVPN Chrome extensions , but for now, more details are not known until they are patched.
