Chrome There are many free extensions in the extension store VPN, but not every one is safe. For example, it was recently reported that FreeVPN.One, which has more than 100,000 users, was revealed to intercept user browsing pictures and send them to unknown developers, which caused great concerns about security and privacy. If you are using this product, we strongly recommend that you stop using it.

Image source: Koi Security
A popular Chrome VPN extension with more than 100,000 users has been revealed to intercept every web page users browse.
FreeVPN.One has been installed over 100,000 times and has even been featured by Google, so many users may find this to be a very safe VPN. However, Koi Security, a foreign information security technology company, recently released a report stating that FreeVPN.One violates user privacy and is not recommended for use:

Koi Security stated that although VPN extensions require permissions such as proxy and storage to achieve core functions, this extension requires more permissions, allowing it to collect user information extensively. Even if the privacy policy mentions it, your information will not be collected or used.
FreeVPN.One also requires three permissions:
Koi Security shows how it works. When the user switches between different web pages, this extension will perform a series of suspicious actions. For example, a few seconds after loading any web page, the background will trigger an action to grab a screenshot and send it to aitd[.]one/brange.php, and then attach the URL of the web page, the page ID, and the unique user identification code:

Image source: Koi Security
These actions are completed silently in the background, and the user will not know at all.
Koi Security found that FreeVPN.One was indeed just a VPN in the past, with no other privacy-threatening content. However, starting from the v3.0.3 version in April 2025, it first added the
In order to avoid detection, in the v3.1.4 version on July 25, 2025, AES-256 encryption, RSA encapsulation, and the scan.aitd.one subdomain were added again, which means that what was once a trustworthy VPN has now become a tool for monitoring network behavior.

Koi Security also contacted the developer and confirmed that the automatic screenshot function is available and is enabled for everyone. It will be changed to user consent in the future. Although the developers emphasized that it would only trigger on suspicious domains, they actually tested it on even Google Spreadsheets and Google Photos.
This report also mentions the statements of other developers, as well as Koi Security’s opinions, and those who are interested can go and read it.
There are many free VPNs on the Internet made by independent developers. Although it does not mean that every one is unsafe, most of them do not have clear privacy policies, and some even use completely unrelated services. Therefore, for users who have VPN needs, we still recommend using VPNs from some well-known companies.
Source: KOCPC Chinese