Is Surfshark VPN Extension safe?

Clean risk

Surfshark VPN Extension sends every visited domain and full email content to Surfshark servers, each tagged with a persistent device identifier.

When the Breach Alert feature is enabled, the extension transmits each domain the user visits to ext.surfshark.com along with a persistent random UUID (stored as 'device-id') that ties requests to the specific installation. When the user clicks 'Check email' in Gmail, the extension collects the email body, subject, sender address, headers, and links and posts them to Surfshark's phishing-scan endpoint. Additionally, the extension intercepts the browser Geolocation API on all HTTP/HTTPS pages when geo-spoofing is active, substituting VPN server coordinates for the user's real GPS position.

Surfshark Appsv5.2.1Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

ext.surfshark.com
Updated 17 September 2026ailoabdmgclmfmhdagmlohpjlbpffblp