# CloakBrowser: a stealth Chromium with C++ fingerprint patches and a Playwright-shaped API

> CloakBrowser ships a real Chromium binary whose fingerprints are modified at the C++ source level, wrapped in a Python and JavaScript API that mirrors Playwright. The install is short; the licence split between the free and Pro builds is where the real decision sits.

**CloakHQ/CloakBrowser** — Stealth Chromium that passes every bot detection test. Drop-in Playwright replacement with source-level fingerprint patches. 30/30 tests passed.

- Repository: https://github.com/CloakHQ/CloakBrowser
- Website: https://cloakbrowser.dev/
- Stars: 31,629 · Forks: 2,625
- Language: Python
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/cloakhq-cloakbrowser

## What CloakBrowser actually is, and who ends up using it

Most anti-detect tooling works by patching a running browser from the outside: a config flag here, a JavaScript injection there. CloakBrowser takes the other route. The README describes it as "a real Chromium binary with fingerprints modified at the C++ source level", and the project ships 73 source-level C++ patches covering canvas, WebGL, audio, fonts, GPU, screen, WebRTC, network timing, automation signals and CDP input behaviour. The claim that follows from that design is narrow and checkable: antibot systems score the browser as an ordinary browser because, at the level they inspect, it is one.

The audience is developers who already automate browsers and have hit a wall. If you write Playwright scripts against sites that run Cloudflare Turnstile, FingerprintJS or BrowserScan, and your scripts fail on the fingerprint rather than on the logic, this project is aimed at you. The same goes for teams running AI agents that need to reach pages behind bot checks. It is not a scraping framework, a proxy service, or a captcha-solving API. It is a browser build plus a thin launcher.

The repository is MIT licensed and was last pushed on 2026-09-06, with a Chromium 151.0.7922.108.4 Pro preview release published on 2026-09-04. The Python package declares itself Production/Stable in its classifiers, which is a claim about the wrapper rather than about any individual target site.

## The mechanism: source-level patches plus a wrapper that decides which binary to fetch

Two layers matter. The lower layer is the Chromium build itself, where the fingerprint changes live in C++. The upper layer is a Python and JavaScript wrapper whose job is to pick a binary, download it, and hand back an object that behaves like a Playwright browser.

Binary selection is driven by licence. The README states that the wrapper auto-downloads the right binary, free or Pro, based on your licence, and that a Pro licence is supplied either as a `license_key` argument (`licenseKey` in JavaScript) or through the `CLOAKBROWSER_LICENSE_KEY` environment variable. Release channels are separate: `release_channel="preview"` or `CLOAKBROWSER_RELEASE_CHANNEL=preview` opts into the newest build, which the README says covers Linux x64 and Linux ARM64 while Windows x64 and macOS track the older 151.0.7922.108.3 line. That platform skew is worth reading twice before you standardise a CI matrix on preview.

Downloading is not a side effect you can ignore. The binary is roughly 200MB, cached locally, and fetched on first run. The Dockerfile makes the trade-off explicit by running `ensure_binary()` during the image build rather than at container start, so the cost lands in the layer cache instead of on every cold start.

The dependency list is short and tells you what the wrapper trusts: `playwright>=1.40`, `httpx>=0.24`, and `cryptography>=41.0`, the last annotated in pyproject.toml as being there to verify an Ed25519 signature on SHA256SUMS before trusting it. That is a deliberate choice to authenticate the downloaded binary rather than accept whatever the CDN returns.

## Installing CloakBrowser and running a first page load

There is a no-install path, which is the fastest way to see whether the binary works on your machine at all. The README gives this command:

```bash
docker run --rm cloakhq/cloakbrowser cloaktest
```

The image is built from `python:3.12-slim` with Node.js added, and it pre-downloads the stealth Chromium binary during the build, so the container does not stall on a 200MB fetch when it starts. It exposes port 9222.

For local Python work, install the package and launch. The README's example is three lines of actual work:

```python
from cloakbrowser import launch

browser = launch()
page = browser.new_page()
page.goto("https://example.com")
browser.close()
```

```bash
pip install cloakbrowser
```

On first run the wrapper downloads the stealth Chromium binary, roughly 200MB, and caches it locally. If you want the wrapper to infer timezone and locale from your proxy's IP, install the optional extra with `pip install 'cloakbrowser[geoip]'`.

For Node, the README pairs the package with a browser driver rather than bundling one:

```bash
npm install cloakbrowser playwright-core
```

Puppeteer users import from a subpath instead: `import { launch } from 'cloakbrowser/puppeteer'`. There is also a community-maintained .NET client on NuGet, added with `dotnet add package CloakBrowser`, which the README attributes to outside maintainers and builds on Microsoft.Playwright.

Migrating existing Playwright code is a one-line change. The README's diff replaces the `sync_playwright().start()` and `pw.chromium.launch()` pair with `from cloakbrowser import launch` and `browser = launch()`, leaving the rest of the script untouched.

## Where CloakBrowser stops helping: headless mode, proxies and platform gaps

The README is unusually direct about a limitation that undercuts its own headline. In the section aimed at sites with anti-bot protection, the recommended flags include `headless=False`, with the comment that some sites detect headless even with the C++ patches applied. So the patched binary is not sufficient on its own for every target; for the hardest ones you are running a headed browser, which means a display server. The Dockerfile accounts for this by installing Xvfb, xdotool and openbox and using an Xvfb entrypoint to support headed mode. If your deployment target cannot run a virtual display, that recommendation is a wall, not a tuning knob.

The same recommended block pairs the browser with a residential proxy, with the README noting the IP should be residential rather than datacenter. `geoip=True` then aligns timezone and locale to that proxy's IP. The proxy is therefore part of the setup, not an optional extra, and the project does not supply one.

Platform coverage is uneven by release channel. The Pro Stable build is listed for Linux x64, Linux ARM64, Windows x64 and macOS, but the README notes macOS remains on the Chromium 150 Stable line while Linux and Windows moved to 151. The preview channel is Linux-only. A team that needs one identical browser version across macOS laptops and Linux CI runners does not get it from the preview channel.

Finally, the strongest published number, a 0.9 reCAPTCHA v3 score, is attached to Pro. The README does not publish an equivalent figure for the free build, so you cannot assume the free binary reaches the same score on the same target.

## CloakBrowser compared with Camoufox and with plain Playwright

The comparison people search for most is against Camoufox, and the difference is architectural rather than cosmetic. Camoufox is a Firefox-based anti-detect browser. CloakBrowser is Chromium, patched at the C++ source level, and the README's framing turns on that distinction: "Not a patched config. Not a JS injection." Choosing between them is largely choosing an engine, and engine choice propagates. Chromium keeps you on the Playwright and Puppeteer APIs that most existing scraping code already uses, which is why the migration here is a one-line diff. A Firefox-based stack means the surrounding tooling, extensions and rendering behaviour are Firefox's.

The comparison against plain Playwright is simpler and more useful. Stock Playwright launches a Chromium build that is trivially identifiable as automated, and the standard workarounds are launch flags and JavaScript injection. CloakBrowser replaces both with a different binary. The cost is that you now depend on a third-party build pipeline, a licence decision, and a 200MB download, and you inherit the project's release cadence instead of Playwright's. If your targets do not run bot detection, plain Playwright is smaller, better documented and has no binary licence attached to it. CloakBrowser only earns its place when fingerprinting is the thing failing.

## Maintenance cost, release cadence and the two licence files

Keeping up with this project means keeping up with Chromium. The recent release list shows three Pro stealth builds inside a month: 151.0.7922.108.2 on 2026-08-18, 151.0.7922.108.3 on 2026-08-27 and 151.0.7922.108.4 on 2026-09-04. That is a rebase treadmill. The README describes rebasing the full patch set onto Chromium 151 for Linux and Windows and re-validating it against reference data, which is work the maintainers do and you inherit. Upgrading is not a version bump you schedule quarterly; it is a moving target, and the preview channel moves faster than the stable one.

The repository carries two licence files: LICENSE and BINARY-LICENSE.md. The Python package metadata declares MIT, but the README's own description of the free and Pro binaries, the licence key, and the gated newest build makes clear that the binary is governed separately from the wrapper source. Anyone adopting this commercially should read BINARY-LICENSE.md before shipping, and treat the MIT classifier in pyproject.toml as covering the Python code only. This is a description of what the repository contains, not legal advice; the terms themselves are in those files.

What the README does not document is rollback. There is no described procedure for pinning the wrapper to a specific Chromium build or reverting after an upgrade breaks a target. The release tags are versioned, so pinning is presumably possible, but the README is silent on it. Teams that need reproducible browser versions should treat that gap as something to resolve before rollout, not after.

## Conclusion

Adopt CloakBrowser if your scraping or agent stack already runs Playwright and you want the fingerprint work done inside the browser rather than through injected JavaScript. Do not adopt it if you need a stable, documented public API surface: the README does not document rollback between builds, and the newest binaries are gated behind a licence key. Before committing, run the no-install Docker test on your actual target, then check whether the free build or the Pro build is the one that passes it, and read BINARY-LICENSE.md alongside LICENSE because the two files cover different things.

## FAQ

### How do I install CloakBrowser?

For Python, run pip install cloakbrowser; on first run the wrapper downloads the stealth Chromium binary, roughly 200MB, and caches it locally. For Node, install cloakbrowser together with playwright-core or puppeteer-core. There is also a no-install Docker route via docker run --rm cloakhq/cloakbrowser cloaktest.

### What is CloakBrowser?

It is a stealth Chromium build with fingerprints modified at the C++ source level, shipped with a drop-in Playwright and Puppeteer replacement for Python and JavaScript. The project describes 73 source-level patches covering canvas, WebGL, audio, fonts, GPU, screen, WebRTC and automation signals.

### Is CloakBrowser safe to use?

The Python package depends on cryptography to verify an Ed25519 signature on SHA256SUMS before trusting the downloaded binary, which is a deliberate check on the download. Note that the repository has two licence files, LICENSE and BINARY-LICENSE.md, and the MIT metadata covers the wrapper code rather than the binary.

### How does CloakBrowser compare with Camoufox?

Camoufox is a Firefox-based anti-detect browser, while CloakBrowser is Chromium patched at the C++ source level. The practical difference is the engine: CloakBrowser keeps you on the Playwright and Puppeteer APIs, which is why the README's migration is a one-line import change.

### How does CloakBrowser differ from Playwright?

The API is the same shape, but CloakBrowser launches a different Chromium binary whose fingerprints are patched in C++ rather than left stock. Plain Playwright has no binary licence and a smaller install; CloakBrowser adds a 200MB download and a licence decision in exchange for the fingerprint work.

### How do I use CloakBrowser on sites with anti-bot protection?

The README recommends adding a residential proxy, setting geoip=True to match timezone and locale to the proxy IP, setting headless=False, and enabling humanize=True for human-like mouse, keyboard and scroll behaviour. It notes that some sites detect headless even with the C++ patches applied.

## Sources

- [CloakHQ/CloakBrowser on GitHub](https://github.com/CloakHQ/CloakBrowser)
- [License: MIT](https://github.com/CloakHQ/CloakBrowser/blob/main/LICENSE)
- [Project website](https://cloakbrowser.dev/)
- [README](https://github.com/CloakHQ/CloakBrowser/blob/main/README.md)
- [Releases](https://github.com/CloakHQ/CloakBrowser/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/cloakhq-cloakbrowser
