Skip to content
Anomalous Anomalous / Corpus
Browse the docs

Proton VPN – WireGuard Network Extension

This is a background helper that belongs to the Proton VPN app on your Mac. When you use the WireGuard protocol (or Smart Protocol) in Proton VPN, macOS requires a dedicated network extension to handle the encrypted VPN tunnel. That extension — identified by the bundle prefix "ch.protonvpn.mac" — runs quietly in the background, outside the core of macOS, to keep your internet traffic routed securely through Proton's servers. Proton VPN is made by Proton AG, a Swiss privacy company, and WireGuard is the fast, open-source protocol it uses by default.

ch.protonvpn.mac.WireGuard-Exte — owned by Proton AG.

When it runs hot
Sustained high activity typically means the extension is actively managing a VPN connection — encrypting and routing a large amount of network traffic — or that Proton VPN is renegotiating or reconnecting the tunnel (for example, after a network change or an unstable connection). It can also spike briefly when the WireGuard tunnel is first established.
Safety tier
Caution — User-facing but stateful — look before you act.
Safe action
quit
Worst case
Stopping it while connected drops your VPN tunnel, so your internet traffic temporarily travels without the privacy protection Proton VPN normally provides. Proton VPN can re-establish the connection once you reconnect via the app.

Sources

Sourced by Anomalous — this is the published corpus entry that grounds the ch.protonvpn.mac.WireGuard-Exte diagnosis card, not a language-model guess. Browse the whole process corpus.

Spotted something wrong or missing? Anomalous is open source, and its process corpus takes pull requests. Contribute on GitHub →