Back to the PureVPN review

Research record

What the public record says about PureVPN privacy and security

We read what auditors, courts, security researchers and the press have published about PureVPN, then kept only the claims that two separate sources back. This is a record of what is published, not a lab test.

Claims researched
28
Cleared for this page
7
Separate sources behind them
8
Research completed
October 3, 2026

What the evidence supports

Claims that two or more separate sources back

Each statement below is followed by the sources it rests on. A verdict describes what the sources say. It is not our endorsement.

Servers and protocols

How the servers and connection protocols are built.

Sources agree

PureVPN runs virtual server locations (servers that appear in one country and are hosted in another): Cloudwards counts virtual servers in 25 countries; PCWorld noted a few in 2021.

2 separate sources: Cloudwards and PCWorld

Sources and caveats (2)
  1. Cloudwards · Analysis · Published June 19, 2024

    Virtual servers in 25 countries

    Counts toward the two-source rule

    Conflict of interest: Affiliate-supported review site; reached out to PureVPN for comment (relays PureVPN's reply)

  2. PCWorld · Press report · Published January 12, 2021

    PureVPN has some good speeds, its privacy policy says it doesn't keep many logs, there's a renewed app, but it does use a few virtual server locations which some users may not like.

    Counts toward the two-source rule

    Conflict of interest: Review pages may carry affiliate links

Researcher notes

Privacy relevance: legal jurisdiction follows the server's physical location, not its label. Counts differ by date (a few in 2021, 25 countries in the 2026 review); the number is a snapshot of one review. PureVPN itself marks virtual servers with a 'v' on its server page per Cloudwards; not independently checked.

Ownership and jurisdiction

Where the company is incorporated, who owns it, and which laws reach it.

Sources agree

PureVPN moved its headquarters from Hong Kong to the British Virgin Islands; PureVPN dates the decision to early 2021 and announced the move on 2021-11-05. Its privacy policy names GZ Systems Ltd, Road Town, Tortola, BVI.

2 separate sources: Cloudwards and PCWorld

Sources and caveats (4)
  1. PureVPN (purevpn.com blog) · Provider own statement · Published November 5, 2021

    We analyzed multiple locations and held talks with various authorities in over 17 different countries to see if they could be the right fit for us.

    Listed for context, adds no independence

    Conflict of interest: Page meta date is 2024-01-01 (republish); 2021-11-05 from the Newswire release of the same text

  2. PureVPN · Provider own statement · No publication date stated

    PureVPN and/or GZ Systems Private Ltd Intershore Chambers, P.O Box 4342 Road Town, Tortola, VG1110 British Virgin Islands.

    Listed for context, adds no independence

    Conflict of interest: Provider's own statement of what it says, not evidence it is true

  3. Cloudwards · Analysis · Published June 19, 2024

    PureVPN's parent company moved its headquarters from Hong Kong to the British Virgin Islands in 2021.

    Counts toward the two-source rule

    Conflict of interest: Affiliate-supported review site; reached out to PureVPN for comment (relays PureVPN's reply)

  4. PCWorld · Press report · Published January 12, 2021

    PureVPN is officially based in Hong Kong and is owned and operated by GZ Systems Limited.

    Counts toward the two-source rule

    Conflict of interest: Review pages may carry affiliate links

Researcher notes

Two independent groups (Cloudwards for the move; PCWorld for the Hong Kong position before it, Jan 2021). The move date itself comes from PureVPN. The BVI company registry was not consulted. Note the company is a BVI address while the team is mostly in Pakistan (T5-02), so 'jurisdiction' in practice is the legal seat only.

Incidents and vulnerabilities

Breaches and published software flaws, and how they came to light.

Sources disagree or leave it open

CVE-2018-6822: the PureVPN macOS client (6.0.1) exposed an unprotected XPC service allowing root command execution (CVSS 9.8). VerSprite reported it on 2018-01-29; a patched build supplied on 2018-02-04 still contained the flaw on 2018-02-06; final remediation status was not found.

2 separate sources: NIST National Vulnerability Database and VerSprite Security

Sources and caveats (2)
  1. NIST National Vulnerability Database · Regulator record · No publication date stated

    In PureVPN 6.0.1 on macOS, HelperTool LaunchDaemon implements an unprotected XPC service that can be abused to execute system commands as root.

    Counts toward the two-source rule

  2. VerSprite Security (GitHub advisory) · Audit report · Published February 7, 2018

    PureVPN provided updated an patched version for validation, however the vulnerability appears to still be present.

    Counts toward the two-source rule

    Conflict of interest: Researcher's advisory; vendor not asked to comment on the page

Researcher notes

Verdict mixed because the last evidence on file (2018-02-07) is 'still vulnerable'; a later fix was not located. NVD lists the affected version as 6.0.1, the advisory title says '< 6.0.1'; NVD scores 9.8 under CVSS 3.0.

Sources disagree or leave it open

CVE-2018-10204: PureVPN 6.0.1 for Windows let any local user write the OpenVPN config read by a SYSTEM service, allowing code execution as SYSTEM (CVSS 8.8). VerSprite states PureVPN repeatedly submitted the same vulnerable build as a fix in April 2018.

2 separate sources: NIST National Vulnerability Database and VerSprite Security

Sources and caveats (2)
  1. NIST National Vulnerability Database · Regulator record · No publication date stated

    This file allows "Write" permissions to users in the "Everyone" group.

    Counts toward the two-source rule

  2. VerSprite Security (GitHub advisory) · Audit report · Published April 18, 2018

    The vendor has failed to resolve vulnerabilities, instead repeatedly submitting the same vulnerable version for testing

    Counts toward the two-source rule

    Conflict of interest: Researcher's advisory; vendor not asked to comment on the page

Researcher notes

The 'failed to resolve' wording is the researcher's account; PureVPN's side of the April 2018 exchange is only summarized in the timeline ('Vulnerability resolved in latest update'). No later fix confirmation found. CVE-2018-18656 (same file area, v6.1.0) shows a later Windows release did change credential handling.

Sources agree

CVE-2018-18656: PureVPN for Windows before 6.1.0 stored the user's login and password in plaintext in a file readable by all local users. Disclosed to PureVPN in mid-August 2017; a patch followed in June 2018 (v6.1.0).

2 separate sources: NIST National Vulnerability Database and SecurityWeek

Sources and caveats (2)
  1. NIST National Vulnerability Database · Regulator record · No publication date stated

    The PureVPN client before 6.1.0 for Windows stores Login Credentials (username and password) in cleartext.

    Counts toward the two-source rule

  2. SecurityWeek · Press report · Published September 28, 2018

    The issues were disclosed to the vendor in mid-August 2017. A patch was released in June 2018.

    Counts toward the two-source rule

    Conflict of interest: Reports Trustwave SpiderLabs research (Trustwave original page is now 404)

Researcher notes

SecurityWeek relays Trustwave SpiderLabs (researcher Manuel Nader); the original Trustwave post is no longer served, so the primary researcher text was not read. Search summaries say a second Trustwave issue (password shown in the config window, 'Show Password') was risk-accepted by the vendor; that is not in the SecurityWeek lines quoted and was not verified. About ten months passed between disclosure and patch.

Sources agree

In November 2023 researchers reported two flaws in PureVPN's Linux desktop client: a DNS leak outside the tunnel (CVE-2023-48957, CVSS 5.3), which PureVPN fixed, and a code-execution path via a missing library lookup, which PureVPN declined to fix, attributing it to Chromium.

2 separate sources: Miscellaneous Ramblings of a Cyber Security Researcher and NIST National Vulnerability Database

Sources and caveats (3)
  1. Miscellaneous Ramblings of a Cyber Security Researcher (Rafay Baloch) · Audit report · Published November 1, 2023

    PureVPN responded by acknowledging the IP leak vulnerability and fixed it in the subsequent release.

    Counts toward the two-source rule

    Conflict of interest: Researcher's own write-up; quotes PureVPN's reply

  2. NIST National Vulnerability Database · Regulator record · No publication date stated

    PureVPN Linux client 2.0.2-Productions fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and be sent directly to the ISP or default DNS servers.

    Counts toward the two-source rule

  3. Latest Hacking News · Press report · Published November 13, 2023

    While PureVPN patched one flaw, another RCE vulnerability remains unpatched.

    Listed for context, adds no independence

    Conflict of interest: Restates Baloch's post

Researcher notes

Two counted groups (researcher post, NVD). 'Won't fix' and PureVPN's reply are as relayed by the researcher; the RCE has no CVE in NVD. NVD published the DNS CVE on 2024-08-25, nine months after the post. The researcher's post carries no date on the page; November 2023 is from its URL and LatestHackingNews (2023-11-13).

Sources agree

CVE-2025-59691 and CVE-2025-59692: PureVPN's Linux clients (GUI 2.10.0, CLI 2.0.1) leaked IPv6 traffic after Wi-Fi reconnect or resume, and flushed existing iptables rules without restoring them. PureVPN confirmed both in a 2025-09-19 advisory; the researcher verified the IPv6 fix in GUI v2.11.0.

3 separate sources: Anagogistis, PureVPN, and NIST National Vulnerability Database

Sources and caveats (4)
  1. Anagogistis (personal blog) · Audit report · Published September 17, 2025

    PureVPN provided a new Linux GUI client build (v2.11.0) on October 19 for validation. I tested it today and confirmed that the IPv6 leak issue appears resolved

    Counts toward the two-source rule

    Conflict of interest: Individual researcher's blog; self-published

  2. PureVPN (purevpn.com blog) · Provider own statement · Published September 19, 2025

    We have validated two issues in our Linux clients (GUI v2.10.0 and CLI v2.0.1):

    Counts toward the two-source rule

    Conflict of interest: Provider's own disclosure

  3. NIST National Vulnerability Database · Regulator record · No publication date stated

    PureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon network events such as Wi-Fi reconnect or system resume.

    Counts toward the two-source rule

  4. CyberInsider · Press report · Published September 22, 2025

    PureVPN on Linux Leaks IPv6 Traffic and Tampers with Firewalls

    Listed for context, adds no independence

    Conflict of interest: Restates the researcher's post (CyberInsider is owned by Resolute Tech, a VPN vendor)

Researcher notes

Three groups: researcher, PureVPN's own advisory (an admission, counted as supporting), NVD. NVD scores both 3.7 (Low). The researcher confirmed only the GUI IPv6 fix; the firewall-reset fix and the CLI client were not confirmed in what was read. Quick, public, specific disclosure by PureVPN (advisory 2 days after the post, patch within ~30 days).

What we cannot yet show

Where the record is thin

A claim stays off this page until two separate sources back it and an editor has cleared its wording. Each dot is one claim we researched. A filled dot is on this page. A hollow dot is not, yet.

  • Logging and no-logs audits0 of 6 shown
  • Security reviews0 of 1 shown
  • Servers and protocols1 of 3 shown
  • Ownership and jurisdiction1 of 3 shown
  • Incidents and vulnerabilities5 of 9 shown
  • Legal actions0 of 4 shown
  • Transparency0 of 2 shown

Not shown means one of two things: fewer than two separate sources, or still waiting for an editor to settle the wording or check a document. It does not mean the claim is false.

How this feeds the Trust Score

The evidence trail behind the number

The Trust Score has a criterion for security track record: audits, breaches and incidents. This page is the written trail for that kind of question, showing what was published, by whom, and how many separate sources agree.

Points are still assigned by the published formula. Read how in the methodology.

How the Trust Score works

See every published research record

How we research

Four rules we hold ourselves to

  1. Two separate sources, minimum

    Two outlets repeating one press release count as one source. Independence is decided by where the information came from, not by how many sites carry it.

  2. Primary documents first

    Auditor reports, court filings and regulator records come before commentary. A provider own page is evidence of what the provider says, never proof that it is true.

  3. Nothing found is a result

    When a search turns up nothing we record what we searched. We never present an empty search as a clean bill of health.

  4. No softening for partners

    A finding that the evidence qualifies is recorded as qualified, whoever the provider is.

VPN.com does not run its own testing lab. Every audit listed here was commissioned and paid for by the provider it examined, and we say so where it applies. We earn commission from some providers; see our disclosures.Read our disclosures