Is Surfshark VPN Extension safe?
Surfshark VPN Extension sends every visited domain and full email content to Surfshark servers, each tagged with a persistent device identifier.
When the Breach Alert feature is enabled, the extension transmits each domain the user visits to ext.surfshark.com along with a persistent random UUID (stored as 'device-id') that ties requests to the specific installation. When the user clicks 'Check email' in Gmail, the extension collects the email body, subject, sender address, headers, and links and posts them to Surfshark's phishing-scan endpoint. Additionally, the extension intercepts the browser Geolocation API on all HTTP/HTTPS pages when geo-spoofing is active, substituting VPN server coordinates for the user's real GPS position.
Who publishes itSurfshark B.V. - no other listings under this identity, 9 shared hostnames
Surfshark B.V. - no other listings under this identity, 9 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 9 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Where it sends data
Destinations our analysis observed Surfshark VPN Extension contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- ext.surfshark.com
Surfshark VPN Extension sends data to ext.surfshark.com. 2 other extensions we have analysed send data here.