Back to the TunnelBear review

Research record

What the public record says about TunnelBear privacy and security

We read what auditors, courts, security researchers and the press have published about TunnelBear, then kept only the claims that two separate sources back. This is a record of what is published, not a lab test.

Claims researched
24
Cleared for this page
11
Separate sources behind them
4
Research completed
October 3, 2026

What the evidence supports

Claims that two or more separate sources back

Each statement below is followed by the sources it rests on. A verdict describes what the sources say. It is not our endorsement.

Security reviews

Penetration tests and code reviews of the apps and servers.

Sources agree

Cure53 performed two full white-box assessments of TunnelBear between November 2016 and June 2017 and published a summary: the 2016 round found 3 Critical and 3 High issues (VPN bypass in the browser extension, local root escalation on macOS); the 2017 round found no Critical and 1 High.

2 separate sources: Cure53 and SecurityWeek

Sources and caveats (3)
  1. Cure53 · Audit report · Published July 25, 2017

    After undergoing the first challenging security test which ended with several critical & high severity findings, the TunnelBear team seems to have redoubled efforts on security.

    Counts toward the two-source rule

    Conflict of interest: Provider is the audit client and pays Cure53; this is the provider describing its own audit; the report is a summary and omits the medium, low and informational detail

  2. SecurityWeek · Press report · Published August 17, 2017

    Experts discovered that the browser extension VPN could easily be turned off by getting the targeted user to access a specially crafted webpage.

    Counts toward the two-source rule

  3. TunnelBear (tunnelbear.com blog) · Provider own statement · Published August 7, 2017

    Cure53, a respected security company, to do a complete audit of our servers, apps and infrastructure.

    Listed for context, adds no independence

Researcher notes

Cure53's summary lists the 2016 criticals (browser-extension URL-matching VPN bypass, extension toggled off by a web page, macOS daemon local root escalation) and 2016 totals: 3 Critical, 3 High, 13 Medium, 8 Low, 13 Informational. 2017: 0 Critical, 1 High (credential files with overly generous permissions on a VPN server, fixed the day it was reported), 4 Medium, 3 Low, 5 Informational. DISCREPANCY: TunnelBear's 2017 blog says 'All vulnerabilities represented low-risk findings' for the 2017 audit, whereas Cure53 records 1 High and 4 Medium. The audit client (TunnelBear) pays Cure53 and, per its own blog, could comment on the draft before publication; the public 2017 summary omits medium/low detail (a companion appendix PDF exists, not read). TunnelBear describes this as the first public third-party audit of a consumer VPN's full infrastructure; that 'first' is a provider claim not independently tested here.

Sources agree

Cure53's October 2018 assessment of TunnelBear found 22 security-relevant issues, including 2 Critical (local root/SYSTEM escalation on macOS and Windows clients); Cure53 concluded security had 'improved by leaps and bounds'.

2 separate sources: Cure53 and TunnelBear

Sources and caveats (2)
  1. Cure53 · Audit report · Published October 21, 2018

    All in all, the security at TunnelBear has once again improved by leaps and bounds.

    Counts toward the two-source rule

    Conflict of interest: Provider is the audit client and pays Cure53; this is the provider describing its own audit

  2. TunnelBear (tunnelbear.com blog) · Provider own statement · Published October 23, 2018

    they discovered 2 “critical”, 5 “high”, 3 "medium", 7 "low", and a few "informational" issues - all of which were promptly fixed.

    Counts toward the two-source rule

Researcher notes

Cure53: 'twenty-two security-relevant issues', twelve vulnerabilities and twelve general weaknesses (the report's own arithmetic). TunnelBear's blog lists 2 Critical, 5 High, 3 Medium, 7 Low plus informationals. Both agree on the criticals. TechNadu coverage of this audit (a VPN-review site) surfaced in search but its text could not be parsed and it is not counted.

Sources agree

Cure53's November 2019 assessment (37 person-days, 10 testers) found 12 security-relevant items including 2 Critical (a macOS TOCTOU privilege escalation and a backend issue) and concluded the security posture was 'sound and generally solid'.

2 separate sources: Cure53 and TunnelBear

Sources and caveats (2)
  1. Cure53 · Audit report · Published January 29, 2020

    the security posture of the tested TunnelBear components is sound and generally solid.

    Counts toward the two-source rule

    Conflict of interest: Provider is the audit client and pays Cure53; this is the provider describing its own audit

  2. TunnelBear (tunnelbear.com blog) · Provider own statement · Published January 28, 2020

    In total, Cure53 found 2 Critical, 4 High, 1 Medium, 2 Low and 3 Informational issues-which were all fixed promptly.

    Counts toward the two-source rule

Researcher notes

Cure53 describes the work as a fix verification rather than a full retest, and wrote that TunnelBear moved 'from being just average to becoming a clear frontrunner among its VPN competitors when it comes to security'. That comparative phrase is Cure53's opinion, quoted by TunnelBear; no other VPN's audit was compared by us.

Sources agree

Cure53's October 2020 assessment (40 person-days, 9 testers) found 19 findings: 0 Critical, 1 High (FilterPods network restrictions), 5 classed as vulnerabilities and 14 as general weaknesses.

2 separate sources: Cure53 and TunnelBear

Sources and caveats (2)
  1. Cure53 · Audit report · Published November 12, 2020

    The testing team was unable to spot Critical issues during this 2020 exercise. Only one flaw was graded as a High risk, while the remaining problems were located in the realm of Medium and lower severity scores.

    Counts toward the two-source rule

    Conflict of interest: Provider is the audit client and pays Cure53; this is the provider describing its own audit

  2. TunnelBear (tunnelbear.com blog) · Provider own statement · Published May 31, 2021

    after 40 days of testing, Cure53 found two low, two medium and one high-risk vulnerability.

    Counts toward the two-source rule

Researcher notes

The blog's five (2 Low, 2 Medium, 1 High) matches Cure53's 'security vulnerabilities' list (TB-08-001, -007, -010, -011, -019); the blog does not mention the 14 miscellaneous findings, several of them Medium AWS configuration issues. Cure53's 2020 PDF is still linked from cure53.de.

Sources agree

Cure53's November-December 2021 assessment (report TB-09, published 28 June 2022) found 32 issues including 3 Critical (stored DOM-XSS in the admin panel and two remote-code-execution paths) and 3 High, and flagged unmitigated findings from earlier audits.

2 separate sources: Cure53 and TunnelBear

Sources and caveats (2)
  1. Cure53 · Audit report · Published June 28, 2022

    The Critical-assigned issues have increased in addition, with three unearthed during this report. Similarly, the volume of High severity-rated issues (also three) has risen in comparison with previous engagements.

    Counts toward the two-source rule

    Conflict of interest: Provider is the audit client and pays Cure53; this is the provider describing its own audit

  2. TunnelBear (tunnelbear.com blog) · Provider own statement · Published July 8, 2022

    Cure53 found four low, nine medium, three high, and three critical-risk vulnerabilities.

    Counts toward the two-source rule

Researcher notes

Cure53 lists 3 Critical (TB-09-001 stored DOM-XSS admin panel; TB-09-009 RCE via partner mapping script; TB-09-026 RCE on IPSec authentication script) and 3 High (TB-09-010, -012, -018) among 32 findings. TunnelBear's blog quotes only 19 (4+9+3+3) and so omits 13 informational/other items, and says all medium-and-above issues were 'quickly resolved'; yet TB-09-025 records earlier-audit vulnerabilities still unmitigated or only partly fixed, including TB-06-002 (insecure keychain deserialisation). Cure53's prose and its own index disagree on the vulnerability/weakness split (prose 20/12; index lists 12 under Vulnerabilities); only the total of 32 and the severity tags are relied on. The report was published about 6 months after testing. Cure53 wrote that the rise in volume and severity 'arguably corroborates the essential need for frequent and thorough testing'.

Sources agree

Cure53's October-November 2022 assessment (report TB-10, published 18 May 2023) found 32 issues including 2 Critical and 8 High, among them a full Ansible Vault secrets disclosure from a VPN server and exposure of DigitalOcean, Vultr and AWS cloud-account credentials; Cure53 said there was 'ample leeway for hardening improvement'.

2 separate sources: Cure53 and TunnelBear

Sources and caveats (2)
  1. Cure53 · Audit report · Published May 18, 2023

    The fact that two Critical ranked vulnerabilities and eight High severity issues were unveiled during this assessment compounds this worrisome viewpoint.

    Counts toward the two-source rule

    Conflict of interest: Provider is the audit client and pays Cure53; this is the provider describing its own audit

  2. TunnelBear (tunnelbear.com blog) · Provider own statement · Published May 19, 2023

    Upon completion of their audit, Cure53 flagged a total 32 issues.

    Counts toward the two-source rule

Researcher notes

Critical: TB-10-001 (blog.tunnelbear.com subdomain takeover; fixed during testing) and TB-10-027 (all Ansible Vault secrets readable on a server). High (8): TB-10-017, -018, -019, -020, -028, -029, -031, -032 (local root escalations, unrestricted HTTP forward proxy access, cloud account compromises, secrets in ECS task definitions). TunnelBear's post reports '15 security vulnerabilities', '27 of the reported vulnerabilities have been resolved' and five remaining, and does not mention the 2 Critical or 8 High; the report's 27 'Fix Note' entries are consistent with the 27 resolved. TB-10-027 carries a fix note as of publication. The blog highlights frontend performance being 'commended'. Exploitation of these issues in the wild was not searched for and nothing is claimed either way.

Sources disagree or leave it open

Cure53's October-November 2023 assessment (published 7 February 2024) found 13 issues with 0 Critical and 2 High (VPN client-listing service reachable via HTTP proxy; VPN access via unauthenticated token generation), and noted that some earlier flaws had been 'incorrectly resolved or simply ignored'.

2 separate sources: Cure53 and TunnelBear

Sources and caveats (2)
  1. Cure53 · Audit report · Published February 7, 2024

    some flaws located in prior audits have either been incorrectly resolved or simply ignored, which are all congregated in ticket TB-11-005.

    Counts toward the two-source rule

    Conflict of interest: Provider is the audit client and pays Cure53; this is the provider describing its own audit

  2. TunnelBear (tunnelbear.com blog) · Provider own statement · Published February 14, 2024

    Specifically, Cure53 reported a total of 6 informational/low-risk issues, 5 medium-risk issues, 2 high-risk issues, and 0 critical-risk issues.

    Counts toward the two-source rule

Researcher notes

Verdict mixed because the provider's framing and the auditor's diverge: TunnelBear says '12 out of the 13 identified issues have been fixed or mitigated' and 'a marked security improvement with each passing round'; Cure53 agrees on the improvement but TB-11-005 (rated Medium) records earlier vulnerabilities, including TB-08-019 (known plaintext attack on sendLogs in AES, unchanged iOS code) and an unencrypted Android database holding the vpn_token and the user's email, still present. Counts agree between the two (2 High, 5 Medium, 6 Low/Info). The 2023 report was the last full report found on cure53.de.

Servers and protocols

How the servers and connection protocols are built.

Sources agree

TunnelBear's apps support OpenVPN and WireGuard (the provider also lists IKEv2); Cure53 reports reference OpenVPN components and a WireGuard public-key finding.

2 separate sources: TunnelBear and Cure53

Sources and caveats (2)
  1. TunnelBear (tunnelbear.com) · Provider own statement · No publication date stated

    Control how you connect to TunnelBear's secure and fast VPN network with WireGuard, OpenVPN, and IKEv2 protocols.

    Counts toward the two-source rule

  2. Cure53 · Audit report · Published June 28, 2022

    TB-09-017 WP6: Absence of certificate wrap for Wireguard public key (Info)

    Counts toward the two-source rule

    Conflict of interest: Provider is the audit client and pays Cure53; this is the provider describing its own audit

Researcher notes

Cure53 2021 (testing Nov-Dec 2021) lists both OpenVPN-related tickets (TB-09-010, TB-09-029) and the WireGuard ticket TB-09-017. IKEv2 and 'AES 256-bit by default' rest on the provider's own page. TunnelBear's WireGuard post says WireGuard has been on Windows and iOS since early 2022 and on all platforms later; the two sources are consistent only loosely on timing.

Ownership and jurisdiction

Where the company is incorporated, who owns it, and which laws reach it.

Sources agree

McAfee announced the acquisition of TunnelBear on 8 March 2018 (assets of the Canadian company, terms undisclosed); TunnelBear says it became TunnelBear LLC, part of a US company, while its offices remain in Toronto.

2 separate sources: TechCrunch and TunnelBear

Sources and caveats (2)
  1. TechCrunch · Press report · Published March 8, 2018

    Security giant McAfee is acquiring Canadian VPN provider TunnelBear. Terms of the deal haven’t been disclosed.

    Counts toward the two-source rule

  2. TunnelBear (tunnelbear.com blog) · Provider own statement · Published November 6, 2018

    As TunnelBear LLC, we are now part of a security company based in the United States, but our offices are still located in Toronto.

    Counts toward the two-source rule

Researcher notes

Date nuance: TechCrunch is dated 8 March 2018 (the announcement); TunnelBear's November 2018 post says it was acquired 'in April 2018' (closing, per Dark Reading headline 'McAfee Closes Acquisition', not read: HTTP 403). TechCrunch's own commentary: TunnelBear 'will have to comply with U.S. laws'. TunnelBear's privacy policy (2026) names the contracting entity 'TunnelBear LLC.' and says personal data is stored only inside Canada and governed by Canada's laws; a Delaware LLC claim from search summaries was not verified against a filing.

Sources agree

TunnelBear is exposed to both Canadian and US legal process: it says it operates from Toronto, states personal data is held only in Canada under Canadian law, is owned by a US company, and acknowledges that it must comply with valid subpoenas; its 2025 post argues jurisdiction matters less than having no data to hand over.

2 separate sources: TunnelBear and TechCrunch

Sources and caveats (2)
  1. TunnelBear (tunnelbear.com blog) · Provider own statement · Published March 29, 2021

    Since TunnelBear is located in Canada, we have to obey Canadian data laws. If we receive a subpoena, we’re obligated to respond and cooperate to the best of our ability.

    Counts toward the two-source rule

  2. TechCrunch · Press report · Published March 8, 2018

    But TunnelBear is based in Canada, which could be an issue if you’re trying to avoid intelligence services.

    Counts toward the two-source rule

Researcher notes

TunnelBear's own posts name Canada as a Five Eyes member (2020 report) and say 'VPN companies in any country ... must comply with lawful court orders' (2025). Data-retention law exposure was not researched beyond the provider's statements: the Canadian and US data-retention or lawful-intercept statutes were not read. Treat the legal-exposure picture as incomplete. No claim is made that Canada or the US forces TunnelBear to log.

Transparency

What the provider publishes about requests and bug reports.

Sources agree

TunnelBear publishes human-readable transparency reports (2018, 2019, 2020, 2021-2023) and annual Cure53 audit write-ups with full reports through 2023; it reports an audit cadence of nine years (2016-2025) but no transparency report after November 2023 was found.

2 separate sources: TunnelBear and Cure53

Sources and caveats (2)
  1. TunnelBear (tunnelbear.com blog) · Provider own statement · Published November 8, 2023

    It's been some time since our last Transparency Report in 2021.

    Counts toward the two-source rule

  2. Cure53 · Audit report · Published February 7, 2024

    Pentest-Report TunnelBear VPN Clients & Servers 10-11.2023

    Counts toward the two-source rule

    Conflict of interest: Provider is the audit client and pays Cure53; this is the provider describing its own audit

Researcher notes

The 2023 post itself says the previous report (2020 data) was published 'some time' earlier, i.e. a gap of about two and a half years between reports. Auditor-published full reports exist for 2017-2023 only (see T4-08).

What we cannot yet show

Where the record is thin

A claim stays off this page until two separate sources back it and an editor has cleared its wording. Each dot is one claim we researched. A filled dot is on this page. A hollow dot is not, yet.

  • Logging and no-logs audits0 of 1 shown
  • Security reviews7 of 8 shown
  • Servers and protocols1 of 3 shown
  • Ownership and jurisdiction2 of 4 shown
  • Incidents and vulnerabilities0 of 4 shown
  • Legal actions0 of 2 shown
  • Transparency1 of 2 shown

Not shown means one of two things: fewer than two separate sources, or still waiting for an editor to settle the wording or check a document. It does not mean the claim is false.

How this feeds the Trust Score

The evidence trail behind the number

The Trust Score has a criterion for security track record: audits, breaches and incidents. This page is the written trail for that kind of question, showing what was published, by whom, and how many separate sources agree.

Points are still assigned by the published formula. Read how in the methodology.

How the Trust Score works

See every published research record

How we research

Four rules we hold ourselves to

  1. Two separate sources, minimum

    Two outlets repeating one press release count as one source. Independence is decided by where the information came from, not by how many sites carry it.

  2. Primary documents first

    Auditor reports, court filings and regulator records come before commentary. A provider own page is evidence of what the provider says, never proof that it is true.

  3. Nothing found is a result

    When a search turns up nothing we record what we searched. We never present an empty search as a clean bill of health.

  4. No softening for partners

    A finding that the evidence qualifies is recorded as qualified, whoever the provider is.

VPN.com does not run its own testing lab. Every audit listed here was commissioned and paid for by the provider it examined, and we say so where it applies. We earn commission from some providers; see our disclosures.Read our disclosures