Sources agree
Cure53 performed two full white-box assessments of TunnelBear between November 2016 and June 2017 and published a summary: the 2016 round found 3 Critical and 3 High issues (VPN bypass in the browser extension, local root escalation on macOS); the 2017 round found no Critical and 1 High.
2 separate sources: Cure53 and SecurityWeek
Sources and caveats (3)
After undergoing the first challenging security test which ended with several critical & high severity findings, the TunnelBear team seems to have redoubled efforts on security.
Counts toward the two-source rule
Conflict of interest: Provider is the audit client and pays Cure53; this is the provider describing its own audit; the report is a summary and omits the medium, low and informational detail
Experts discovered that the browser extension VPN could easily be turned off by getting the targeted user to access a specially crafted webpage.
Counts toward the two-source rule
TunnelBear (tunnelbear.com blog)
Cure53, a respected security company, to do a complete audit of our servers, apps and infrastructure.
Listed for context, adds no independence
Researcher notes
Cure53's summary lists the 2016 criticals (browser-extension URL-matching VPN bypass, extension toggled off by a web page, macOS daemon local root escalation) and 2016 totals: 3 Critical, 3 High, 13 Medium, 8 Low, 13 Informational. 2017: 0 Critical, 1 High (credential files with overly generous permissions on a VPN server, fixed the day it was reported), 4 Medium, 3 Low, 5 Informational. DISCREPANCY: TunnelBear's 2017 blog says 'All vulnerabilities represented low-risk findings' for the 2017 audit, whereas Cure53 records 1 High and 4 Medium. The audit client (TunnelBear) pays Cure53 and, per its own blog, could comment on the draft before publication; the public 2017 summary omits medium/low detail (a companion appendix PDF exists, not read). TunnelBear describes this as the first public third-party audit of a consumer VPN's full infrastructure; that 'first' is a provider claim not independently tested here.