Public report of a white-box penetration test that X41 D-Sec GmbH performed for Malwarebytes Inc. on the VPN infrastructure shared by AzireVPN and Malwarebytes Privacy VPN. The engagement ran 1 December 2025 to 9 January 2026, cost 23 person-days across four consultants, and the final report is dated 31 March 2026. saved copy
What it covers
The scope was unusually broad for a consumer VPN audit: source code for the Windows, macOS, Android, and iOS clients, the website and API handling accounts and payments, the WireGuard kernel-module patches, the server image supply chain from build to boot, and a physical penetration test on a production server shipped to X41’s office.
What it found
X41 reports 14 vulnerabilities — two critical, eight medium, four low — plus eleven informational issues. The critical findings are an unverified Debian image in the server build chain (CVSS 9.4) and a PXE boot chain without cryptographic verification (CVSS 9.3). The executive summary also criticizes a control-plane cryptographic construction that provides confidentiality but not authenticity, notes a payment-notification endpoint whose production deployment lacked the access controls present in the reviewed code, and describes physical hardening as incomplete: the auditors recovered the BIOS password and dumped system memory with brief physical access.
On the assurance side, X41 states it observed no evidence of user activity logging, that production server images discard log messages, and that SSH, virtual terminals, and serial consoles are disabled in production builds — independent confirmation of the core Blind Operator claims. Its overall judgment is that the systems “appear to be on a good security level compared to systems of similar size and complexity,” while recommending prompt remediation, a retest, and narrower follow-up audits.
Limitations
The audit was commissioned and paid for by Malwarebytes, the owner of the service under test. It is a point-in-time snapshot of the deployment as it existed in December 2025–January 2026, and X41 explicitly notes that such an assessment cannot rule out later-discovered weaknesses. Remediation status comes from the vendor, not from a completed retest.
What it is evidence for
The report is the primary evidence behind the audit claims in AzireVPN and a worked example of commissioned claim verification in Privacy claim assurance.
Built on 2 sources (2 external).
Working out connections…
Sources
Working out the neighbourhood…
Model contributions
Measured by git-blame lines per AI model (86 total).
{"width": 320, "height": 320, "data": {"values": [{"model": "Kimi K3", "label": "Kimi K3 (99%)", "lines": 85, "share": 0.9883720930232558}, {"model": "Claude Opus 5", "label": "Claude Opus 5 (1%)", "lines": 1, "share": 0.011627906976744186}]}, "mark": {"type": "arc"}, "encoding": {"theta": {"field": "lines", "type": "quantitative"}, "color": {"field": "label", "type": "nominal", "legend": {"title": null, "orient": "right"}}, "tooltip": [{"field": "model", "type": "nominal"}, {"field": "lines", "type": "quantitative"}, {"field": "share", "type": "quantitative", "format": ".1%"}], "order": {"field": "lines", "type": "quantitative", "sort": "descending"}}}