Penetration test confirms the security of ExpressVPN’s Windows app


ExpressVPN has announced that its VPN app for Windows has been given a clean bill of health following an independent security audit conducted last year.
From November to December of last year, the cybersecurity firm F-Secure conducted a penetration test of the company’s Windows client in an attempt to identify any potential security weaknesses within the app. More specifically, ExpressVPN wanted to know if an attacker could use its Windows app to execute code remotely while also ensuring that no user information was disclosed or IP addresses were leaked.
In its security assessment of version 10 of ExpressVPN’s Windows app, F-Secure reported that none of the targeted vulnerabilities were found. According to the report, it was not possible to gain information about the company’s clients or out of network traffic from its app. At the same time, the app itself is not susceptible to Man-in-the-Middle (MitM) attacks, TLS downgrading, packet injection or other methods used to execute code remotely.
Of the security issues flagged by F-Secure, one was low-severity while the others were informational. No critical, high or medium issues were found and ExpressVPN has since fixed the issues raised in the firm’s report. These fixes were also confirmed by F-Secure during a re-test which took place in February of this year.
More audits to come
In addition to letting companies know about potential security flaws in their software and services, VPN audits also make it easier for consumers when it comes to picking out the right VPN for their needs.
While ExpressVPN tests its software internally, the company also regularly engages with independent security experts to assess its products and validate the accuracy of its claims. Going forward, the company plans to conduct even more audits this year on all of its VPN clients, core technology and even its privacy policy.
In the past, ExpressVPN has had audits conducted on its proprietary VPN protocol Lightway, its browser extensions, its build verification process and its in-house technology Trusted Server by both PwC Switzerland and Cure53.
Head of cybersecurity at ExpressVPN, Aaron Engel provided further insight in a blog post on the recent independent security audit from F-Secure as well as the company’s plans for future audits, saying:
“The report from F-Secure showcases the strength of our product and validates the high-quality work that ExpressVPN engineers and security experts have been doing. This is the first of multiple audits to come in 2022, and we are committed to continuing to deliver independent reports on all of our client apps, core technology, privacy policy, and more.”
Audio player loading… ExpressVPN has announced that its VPN app for Windows has been given a clean bill of health following an independent security audit conducted last year. From November to December of last year, the cybersecurity firm F-Secure conducted a penetration test of the company’s Windows client in an…
Recent Posts
- Apple will let parents share their kids’ ages to limit app access
- Perplexity’s voice mode gets a futuristic makeover on your iPhone
- OpenAI announces GPT-4.5, warns it’s not a frontier AI model
- The 5 best mechanical keyboards for 2025
- OpenAI Launches GPT-4.5 for ChatGPT—It’s Huge and Compute-Intensive
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010