Sources agree
Cure53 reviewed Surfshark's Chrome and Firefox extensions in November 2018 (white-box penetration test and code audit, five days, two testers) and reported two security-relevant findings: one Low-severity issue outside the extensions themselves and one informational weakness.
2 separate sources: Cure53 and Surfshark
Sources and caveats (2)
Carried out by Cure53 in November 2018, this project yielded only two security-relevant findings with limited severities and impact.
Counts toward the two-source rule
Conflict of interest: Commissioned by Surfshark (paid engagement); report hosted by Cure53
2018 - audit by Cure53 revealed that our browser extensions stand out for their robust security.
Counts toward the two-source rule
Conflict of interest: Surfshark publishing about itself
Researcher notes
Two groups: Cure53's own report (hosted on cure53.de and in Cure53's public GitHub publications list, same origin) and Surfshark's page. The report is a full public document. Findings: SRF-01-002 (Low), the invitation email linked the download page over unencrypted HTTP, which Cure53 says is 'not even related to the browser extension itself'; SRF-01-001 (Info), unused insecure HTTP branch in proxy config, removed. Scope was the browser extensions only, not the VPN apps or servers. Eight years old: it speaks to 2018 code.