Goldenfrog develops VyprVPN, a consumer-facing virtual private network application, with a narrow but notable vulnerability footprint centered on system interaction and access-control issues. The observed weakness classes—untrusted search paths and incorrect permission assignment for critical resources—reflect typical risks in client software that interfaces with the operating system and manages sensitive credentials. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Goldenfrog over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17809HIGH In Golden Frog VyprVPN before 2.15.0.5828 for macOS, the vyprvpnservice launch daemon has an unprotected XPC service that allows attackers to update the underlying OpenVPN configur | Dec 20, 2017 | 7.8 | 24 | NO | NO |
CVE-2018-13133HIGH Golden Frog VyprVPN before 2018-06-21 has a vulnerability associated with the installation process on Windows. | Jul 4, 2018 | 7.8 | 20 | NO | NO |
CVE-2018-10645HIGH Golden Frog VyprVPN 2.12.1.8015 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "VyprVPN" service. This service establishes a NetNamedPipe endpoint | May 2, 2018 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Goldenfrog.
Media articles that mention a CVE ID that affects a product developed by Goldenfrog — matched by CVE ID, not by vendor name.