NordVPN put under scrutiny the security of all apps – here are the results
Independent auditors have put the security infrastructure of all NordVPN‘s applications under the microscope yet again, showing the provider’s continuous commitment to transparency, privacy and security.
The security audit results come, in fact, only a few weeks after TechRadar’s best VPN provider also proved its no-log claims with a third-party check.
Leading auditing firm Cure53 carried out a series of tests across all NordVPN desktop applications, mobile apps, browser extensions, and some key features. Experts found a total of 31 findings – despite none of them being critical – which the Nord team mostly fixed at the time of writing.
You may like
NordVPN security audit
Experts at Cure53 conducted a mix of penetration and source code reviews between June and August 2024, for a total of fifty-five days.
As mentioned earlier, NordVPN apps (Windows, macOS, Linux, iOS, and Android VPN) and browser extensions (Chrome, Edge, and Firefox) weren’t the only tech to be inspected. Auditors also took apart NordVPN Threat Protection, Threat Protection Pro, and Meshnet.
Cure53 found a total of 31 findings, with 22 being classified as security vulnerabilities (with some ranked as High) and nine as general weaknesses with lower exploitation potential.
“This security assessment revealed a high number of issues. However, given the broad scope included in Cure53’s examination, and the large attack surface it encompassed, a higher than average number of issues was to be expected,” noted auditors in their final report, sharing recommendations to fix these issues.
At the same time, however, auditors observed “the system utilized several well-regarded libraries, including NGHTTP2, OpenSSL, and Boost,” which are known for their stability and security.

On their side, NordVPN has welcomed Cure53 suggestions and already enforced a fix for most of the issues, which was also verified by Cure53.
“Security is at the core of everything we do at NordVPN. Independent assessments like this allow us to continuously refine our technology and stay ahead of emerging threats,” said NordVPN CTO Marijus Briedis, ensuring the team swiftly implemented all necessary improvements to ensure the highest level of protection for users.
Despite the findings, the provider explains, the latest Cure53 assessment has confirmed that NordVPN apps are built on a strong security foundation as no critical issues were found.
The security audits come as the provider confirmed its no-log claims for the fifth time since 2018 back in February. In that instance, experts at Deloitte inspected NordVPN’s server configuration and relevant IT systems to ensure data related to users’ activities is never logged as stated in its privacy policy.
“Our work towards improving security is never finished, and we will keep moving forward,” said Briedis. “We are proud of these results and will keep making NordVPN one of the most secure VPN services available to everyone.”
You can read the full Cure53 report by heading to the user control panel on the provider website or clicking here.
Disclaimer
We test and review VPN services in the context of legal recreational uses. For example: 1. Accessing a service from another country (subject to the terms and conditions of that service). 2. Protecting your online security and strengthening your online privacy when abroad. We do not support or condone the illegal or malicious use of VPN services. Consuming pirated content that is paid-for is neither endorsed nor approved by Future Publishing.
Independent auditors have put the security infrastructure of all NordVPN‘s applications under the microscope yet again, showing the provider’s continuous commitment to transparency, privacy and security. The security audit results come, in fact, only a few weeks after TechRadar’s best VPN provider also proved its no-log claims with a third-party…
Recent Posts
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
- The Instagram Plus subscription has officially launched
- Cyberdecks used to look like little laptops, but now they’re getting more personal
- Canada Prime Minister Mark Carney announces questionable national AI strategy
- Kevin O’Leary agrees to downsize massive Utah data center
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023