Skip to main content
  1. Home
  2. Computing
  3. News

ProtonVPN and NordVPN patched up vulnerabilities before they became known

Add as a preferred source on Google
Mark Coppock/Digital Trends

Following the announcement from Cisco Talos that both NordVPN and ProtonVPN’s internet traffic obfuscating services were vulnerable to a newly discovered bug, both companies have come out with statements of their own to calm the fears of their users. It turns out that the respective flaws were patched out weeks ago, back when no one had heard anything about them.

The flaws in question piggybacked a patch applied by both companies to a bug discovered earlier this year. That April fix had its own flaw in it, according to ZDNet, which made it possible for a theoretical attacker to take control of the user’s system by exploiting the design of both NordVPN and ProtonVPN’s clients. Fortunately, those bugs were patched out well before the general public was made aware of them.

Recommended Videos

“The vulnerability described in their report no longer exists on our systems. When it did, it was completely undocumented and quite possibly unknown to anyone in the world,” NordVPN said on its blog. “When they discovered the CVE vulnerability in our and other VPN providers’ systems, Talos Intelligence, like all ethical security research firms, approached us with the news first before publishing it. They waited until we fixed the problem before publishing their findings to ensure that no VPN users were exposed to any additional risk.”

ProtonVPN released its own statement to ZDNet, claiming that the fix it has now implemented would eliminate all bugs of this type, but it will continue to investigate the issue to make sure.

Also of import is the fact that this particular exploit required hard access to a victim’s machine in the first place. That meant that even if this bug hadn’t been patched out, an attacker would have to have physical or remote access to the machine through a guest account or malware attack to execute the VPN exploit. As NordVPN pointed out in its blog post, if a hacker already has such access to a system, there are many other options they would have to further the attack. This exploit would merely be one extra attack vector.

With that in mind, this security breach wasn’t as damaging as some may have made out, but regardless, it’s good to see companies like NordVPN and ProtonVPN responding so swiftly to the problem.

If you want to make sure that your system is as protected as it can be, just run the updater within your VPN software to download the latest version if it hasn’t done so automatically.

For a look at some of our favorite VPNs, here’s our guide to the best.

Jon Martindale
Jon Martindale covers how to guides, best-of lists, and explainers to help everyone understand the hottest new hardware and…
This GitHub project wants to strip AI watermarks from your content, and things are getting interesting
This open-source tool is trying to remove the fingerprints AI leaves behind
Electronics, Phone, Mobile Phone

AI companies are increasingly looking for ways to mark content generated by their models. Now, someone has built an open-source tool designed to remove some of those marks.

A GitHub project called watermarks-remover is designed to strip different types of AI provenance signals from text and files. According to its documentation, it can work with invisible Unicode characters, statistical text watermarks and metadata embedded in formats including PNG, JPEG, SVG, PDF, DOCX, ODT, HTML and Markdown.

Read more
Lenovo’s answer to the MacBook Neo could be a peppy Vibe laptop
Affordable and eye-catching Lenovo laptops could soon challenge the MacBook Neo
Computer, Electronics, Laptop

Apple's MacBook Neo has given Windows laptop makers something to think about, and Lenovo could be the latest company preparing an answer.

Windows Latest has obtained images of an upcoming budget laptop called the Lenovo IdeaPad Vibe, which is expected to come in both Qualcomm Snapdragon and AMD versions. It also appears Lenovo isn't playing it safe with the design, as the laptop is shown in seven different colors.

Read more
Claude can now pull data from your browser tabs and keep working on your desktop
Claude in Chrome just merged with Cowork for uninterrupted cross device sessions.
claude-chrome-extension-cowork-session

Anthropic just made its Claude browser extension a lot smarter, and it can remember your conversations on desktop, web, or mobile. The Claude in Chrome side panel now runs as a full Claude Cowork session, meaning your conversations, skills, and connectors all carry over between your browser and Claude's desktop, web, and mobile apps. Before this update, browser sessions stayed completely separate from everything else, so switching devices meant starting over.

https://www.youtube.com/watch?v=C-5wF6tkQ2Q

Read more