Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeTikVPN-Super Secure VPN
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Packet-tunnel binary links Firebase Crashlytics, Firebase Sessions, Firebase Installations, Firebase Remote Config and Google Data Transport, sending Google-hosted telemetry (installation ID, session events, crash reports) every time the VPN runs — despite the bundled GoogleService-Info.plist declaring IS_ANALYTICS_ENABLED=false.
  2. 02Packet-tunnel network extension routes all device traffic through TikVPN-operated proxy servers using a Clash-based engine that supports trojan, shadowsocks, reality and mixed protocols.
  3. 03Packet-tunnel binary calls a vendor backend (host fragment b.tikvpn.*) at /api/2/line/connect/ and /api/2/line/connectregion using a stored userToken / userID, providing the vendor with per-user connection metadata (region selection, connect/disconnect events) tied to a stable account identifier.
OTHER EXTENSIONS

Is TikVPN-Super Secure VPN safe?

Medium risk

No summary available.

Tap Connect Inc.v2.3.6Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.tikvpn.mac.PacketTunnel

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact