Sources agree
Cure53 reviewed NordVPN's desktop and mobile apps and add-ons in July-August 2022 (report dated 22 Feb 2023): 22 findings, 6 of them vulnerabilities, including 1 Critical (Linux root privilege escalation) and High-severity macOS issues.
3 separate sources: Cure53, NordVPN, and CyberInsider
Sources and caveats (3)
identifying a total of twenty-two. Six of the findings were categorized as security vulnerabilities, whilst the remaining sixteen were deemed general weaknesses with lower exploitation potential.
Counts toward the two-source rule
All the detected critical, high, and medium severity vulnerabilities were fixed by our restless developers and approved by the Cure53 authority
Counts toward the two-source rule
The relatively typical volume of vulnerabilities detected for a scope of this magnitude indicates that the entire client software complex has already made strong progress from a security perspective.
Counts toward the two-source ruleQuote not yet re-checked against the page
Researcher notes
Primary document read in full. The 'fixed and approved' claim is Nord's; the Cure53 report is the pre-fix state. Nord says all critical/high/medium issues were fixed; the later 2024 report lists 'NOR-15-002 Unpatched vulnerabilities from previous test (Medium)', so at least one earlier finding persisted to mid-2024. The Cure53 conclusion for this scope is 'a mixed impression, with security strengths and weaknesses detected across all work packages'. Sponsor-paid audit.