JustBrowser
Comparisons13 min read

undetected-chromedriver vs Camoufox vs Commercial Antidetect: 2026 Engineering Guide

JustBrowser Platform Team·
undetected-chromedrivercamoufoxpatchrightplaywright-stealthbrowser-automationbuildinpublicsaasstudioaiworkforcebuildwithclaude

Two months ago I spent a weekend debugging a scraper that worked Tuesday, failed Wednesday, worked Thursday, and died permanently Friday. Classic. Cloudflare Turnstile on the target site. My setup: undetected-chromedriver with stealth patches, residential proxies, randomized viewport sizing.

The logs looked fine. Every visible check passed. CreepJS said I was human. But requests kept getting blocked.

Took me embarrassingly long to figure out — longer than I'd like to admit publicly, honestly. The site wasn't checking navigator properties or canvas fingerprints. They were checking TLS cipher suites. And undetected-chromedriver? Doesn't touch TLS. Stock Chromium handshake. Might as well have been waving a flag that said "I'm automated."

I patched around it. Switched to curl-impersonate for the TLS layer. Proxied requests through a local instance. It worked. For two weeks. Then something else broke. Then something else.

Eventually I did the math on hours spent versus subscription costs and felt a little stupid. That's what this post is about — where OSS stealth tools actually hold up, where they leak, and when paying for a commercial antidetect engine makes sense. No judgment either way. I used free tools for years. Sometimes they're still the right call.

Quick Verdict

TL;DR: undetected-chromedriver and Camoufox work against lightweight detection — sites using basic webdriver checks, simple fingerprinting, or no dedicated anti-bot vendor. They fail against TLS fingerprinting (ja3/ja4), HTTP/2 frame ordering checks, worker thread inconsistencies, and detection systems that query below the JavaScript API layer. If your targets run Cloudflare, DataDome, PerimeterX, or Akamai Bot Manager, OSS stealth will keep you in an arms race you'll eventually lose. Commercial tools with native C++ engine patches (not extension-based — actual source modifications) handle these layers. Pick OSS for lightweight targets or early prototyping. Pick commercial when maintenance burden exceeds subscription cost.

The OSS Stealth Landscape in 2026

undetected-chromedriver

The workhorse. pip install undetected-chromedriver and you're running. Patches Chromium to remove navigator.webdriver, randomizes window sizing, handles Chrome's cdc_ markers that Selenium injects.

What it does well:

  • Removes obvious automation signatures
  • Handles Chrome DevTools Protocol exposure
  • Works with standard Selenium code
  • Active maintenance (mostly — though "active" is doing heavy lifting some months)

What it doesn't touch:

  • TLS cipher suite ordering
  • HTTP/2 frame priorities and settings
  • Canvas/WebGL hardware consistency
  • AudioContext oscillator fingerprints
  • Worker thread navigator consistency
  • Font rendering subpixel patterns

That second list? That's where modern detection lives. FingerprintJS Pro, Cloudflare, and DataDome query these layers. undetected-chromedriver passes the JavaScript API checks because it patches those. But when the detection happens at the network layer, you're cooked. We dive deeper into these audio, font, and hardware fingerprinting vectors in a separate post.

I learned this the hard way. Repeatedly.

Camoufox

Different approach. Camoufox patches Firefox at the source code level — actual C++ modifications compiled into the browser. Handles more vectors: canvas noise injection, font enumeration randomization, audio fingerprint spoofing.

Stronger coverage than undetected-chromedriver. But the trade-off:

  • You're building Firefox from source (or trusting pre-built binaries)
  • Updates lag behind Firefox releases by weeks or months
  • The community is smaller — fewer people validating patches
  • Firefox automation is less mature than Chromium automation in most frameworks

When to use it: you need deeper fingerprint spoofing than undetected-chromedriver provides, you're comfortable with Firefox's DevTools Protocol, and you can handle the build/maintenance overhead.

patchright

Community fork of Playwright with stealth patches baked in. Removes webdriver signatures, patches navigator properties, handles some fingerprint vectors. Basically undetected-chromedriver for the Playwright ecosystem.

Same TLS problem. Patchright patches the browser's JavaScript APIs but doesn't modify the network stack. Chrome's TLS handshake remains stock. Sites using ja3/ja4 fingerprinting flag you immediately.

Patchright is great for: targets using Puppeteer-Extra stealth plugin level detection, prototyping scrapers before deciding if you need heavier tooling, Playwright-native workflows where you don't want to context-switch to Selenium.

Feature Comparison: OSS vs Commercial

Capabilityundetected-chromedriverCamoufoxpatchrightCommercial Antidetect (Native Engine)
Webdriver detection✅ Patched✅ Patched✅ Patched✅ Patched
Navigator consistency✅ Basic✅ Full✅ Basic✅ Full (40+ parameters)
Canvas/WebGL❌ Stock✅ Noise injection❌ Stock✅ Hardware-consistent spoofing
Audio fingerprint❌ Stock✅ Spoofed❌ Stock✅ Spoofed
TLS fingerprint (ja3/ja4)❌ Stock Chrome❌ Stock Firefox❌ Stock Chrome✅ Modified cipher ordering
HTTP/2 fingerprint❌ Stock❌ Stock❌ Stock✅ Chromium-consistent
Worker thread consistency❌ Leaks⚠️ Partial❌ Leaks✅ Full isolation
Multi-profile management❌ Manual❌ Manual❌ Manual✅ Built-in
Persistent sessions❌ DIY❌ DIY❌ DIY✅ Cloud sync optional
Headless/GUI consistency⚠️ Varies⚠️ Varies⚠️ Varies✅ Same fingerprint
MaintenanceYouYouYouVendor

The rightmost column assumes native engine commercial tools (like JustBrowser) — not extension-based competitors. Extension-layer antidetect browsers share some of OSS's gaps because they're patching at the same level. We break down the extension vs native antidetect architecture in detail elsewhere.

Where OSS Actually Works

I'm not here to trash free tools. I used them for three years. They work in specific contexts.

Targets without dedicated anti-bot: Sites running basic Selenium detection, checking navigator.webdriver, looking for cdc_ markers. Recipe blogs. Small e-commerce. Local business directories. Academic resources. If the site hasn't paid for Cloudflare Enterprise or DataDome, undetected-chromedriver handles it fine. Hell, most of the internet still doesn't use serious bot detection. We just notice the sites that do because they're the ones that break our stuff.

Prototyping and validation: Building a scraper? Start with patchright. If it works, ship it. Don't pay for tooling you don't need. The commercial upgrade happens when the target hardens detection — not before.

Low-stakes automation: Test accounts. Development environments. Internal tools. Anywhere you're not betting business revenue on detection avoidance.

Limited-run operations: Scrape a dataset once. Research project with defined scope. OSS maintenance burden scales with duration. One-time jobs don't accumulate that debt.

(Side note: I've watched engineers spend three days setting up "proper" commercial tooling for a one-afternoon scrape. Don't be that person.)

Firefox-required targets: Some sites fingerprint specifically for Chromium patterns. Camoufox in Firefox provides different fingerprint signatures. I've seen cases where Camoufox works simply because the detection system optimized for Chrome-shaped traffic.

Where OSS Breaks Down

The TLS Problem (This Is the Big One)

Modern detection correlates multiple layers. Your JavaScript fingerprint says Chrome 125 on Windows 11. Your TLS fingerprint says... stock Chrome. Specifically, stock Chrome on Linux, because that's what your CI server runs, and TLS handshake reveals OS-level TCP/IP behaviors.

Mismatch. Flagged. Annoying as hell when you don't know what's happening.

undetected-chromedriver doesn't modify TLS. patchright doesn't modify TLS. They can't — the TLS stack lives below the browser automation layer. You'd need to intercept at the network level (curl-impersonate, mitmproxy with TLS modification) or patch the browser engine source code.

Commercial antidetect browsers with native C++ engines modify TLS at build time. JustBrowser's Chromium engine has ja3/ja4 fingerprint consistency baked in. That's not a feature we added — it's what happens when you're modifying source code instead of patching runtime APIs.

If your targets run Cloudflare Turnstile, DataDome, PerimeterX, or Akamai Bot Manager, TLS fingerprinting is active. OSS stealth loses here. Not eventually — immediately.

Worker Thread Consistency

Web Workers and Service Workers have their own navigator object. Some detection systems query the main thread, then query a worker, then compare. undetected-chromedriver patches the main thread but not workers. The values differ. Detection flags the inconsistency.

This is solvable in OSS — inject patches into worker scope too. But you're now maintaining worker-specific patches that need to update every time Chrome changes worker initialization. It's another maintenance surface. Ask me how I know. (Actually, don't. The debugging session was four hours I'll never get back.)

Maintenance Burden Math

Here's the real calculation: OSS stealth tools require continuous maintenance. Chrome updates break patches. Detection systems evolve. You're debugging fingerprint leaks instead of building features.

The math I eventually did: 6 hours/month maintaining stealth patches × $150/hour opportunity cost = $900/month in engineering time. JustBrowser Pro = $9.99/month.

Not everyone's math works out this way. If you're running hobby projects, your time might be free. If you're a scraping engineer whose salary doesn't change based on tool choices, OSS makes sense. But if you're making business decisions, factor in your maintenance hours.

I wish someone had told me this earlier. Would've saved me a lot of frustrating weekends.

Headless vs GUI Fingerprint Gaps

Running headless Chromium produces different fingerprints than headed mode. Screen dimensions report differently. GPU queries return different values. Font rendering varies.

Some OSS patches handle this. Most don't handle it consistently. You test in headed mode, ship in headless, and wonder why production is getting blocked. We wrote about headless detection vectors — the gaps are real.

Commercial tools with proper architecture produce identical fingerprints in headless and GUI modes. Same profile, same fingerprint, regardless of launch mode. That consistency matters when you're debugging detection issues. You can test if your antidetect browser is leaking with our verification walkthrough.

When Commercial Makes Sense

You're Hitting TLS Fingerprinting

If your targets correlate ja3/ja4 fingerprints with browser fingerprints, OSS stealth can't help. The network layer isn't patchable from browser automation. You need engine-level modifications.

Check if you're hitting TLS detection: compare your success rate between curl requests (which have different TLS fingerprints) and browser requests. If curl succeeds where browser fails (or vice versa), TLS fingerprinting is likely active.

Multi-Profile Management at Scale

Running 20+ accounts? Session management, cookie isolation, proxy assignment per profile, fingerprint consistency across restarts — OSS requires building all of this yourself.

Commercial tools have multi-profile management built in. JustBrowser's Pro tier includes unlimited profiles with persistent sessions and unlimited cloud sync. That's infrastructure you don't have to build. For teams running ad verification across geos or managing social media accounts at scale, the profile management alone justifies the cost.

You Need API Access for Automation

patchright works with Playwright. undetected-chromedriver works with Selenium. But integrating either into CI/CD pipelines, managing profile state programmatically, launching headless instances via REST API — that's DIY.

JustBrowser Pro includes REST API and CDP access. Spin up profiles via API, manage sessions programmatically, integrate with existing automation infrastructure. Our API quickstart covers the integration patterns. The API access is included at $9.99/month — not gated to higher tiers like some competitors. (That pricing decision was deliberate. Gating developer tooling feels predatory.)

Detection Keeps Changing and You're Tired

Cloudflare updates their detection. Your patches break. You fix them. DataDome adds a new check. Patch again. Chrome 127 changes worker initialization. Patch. Firefox updates font enumeration. Patch.

At some point, you realize you're paying for commercial antidetect with your time instead of your wallet. And your time might be worth more. Or at least you'd rather spend it on something other than reading Chromium commit diffs at 11pm.

The Hybrid Approach

Some engineers run both. OSS for light targets, commercial for hardened ones.

Workflow: prototype with patchright → test against target detection → if it fails, spin up the same automation against a commercial profile → compare fingerprints to identify what's leaking.

This works. I did it for months before going full commercial. The overhead is real (maintaining two setups), but it keeps costs down for mixed target portfolios. Fair warning: you will forget which target uses which setup at least once.

My Honest Recommendation

Start with OSS. Seriously. pip install undetected-chromedriver. See if it works for your targets. Most sites aren't running sophisticated detection. Why pay when free works?

Graduate to commercial when:

  • TLS fingerprinting blocks you
  • Maintenance hours exceed $50-100/month in your time
  • You need multi-profile management without building it
  • Headless/GUI fingerprint inconsistencies keep causing issues
  • You're tired of debugging stealth patches instead of building product

JustBrowser's 7-day trial gives you unlimited profiles with full fingerprint engine access. Test against your targets. Run CreepJS and FingerprintJS Pro in both OSS and commercial. Compare what passes. Data tells you whether the upgrade is worth it for your specific situation.

For targets running aggressive TLS detection, commercial is probably necessary. For recipe blogs and academic databases, OSS is fine forever. (If you're doing ad verification or multi-geo competitor research, commercial profile management saves serious time.)

No shame in either path. I used OSS for years and only switched when the math stopped making sense.

Everyone's math is different.

Frequently Asked Questions

Is undetected-chromedriver still working in 2026?

For basic automation against sites using standard bot detection, yes. Against Cloudflare Turnstile, DataDome, or any platform using TLS fingerprinting, it leaks. The core problem: undetected-chromedriver patches navigator properties and removes webdriver flags, but doesn't touch TLS cipher suites, HTTP/2 frame ordering, or worker thread consistency. Modern detection checks all of those.

What's the difference between Camoufox and undetected-chromedriver?

Camoufox patches Firefox at the source level (C++ modifications), while undetected-chromedriver patches Chromium via runtime JavaScript. Camoufox handles more detection vectors — canvas noise, font rendering, audio context — but requires you to build Firefox from source or use pre-built binaries. undetected-chromedriver is pip install and go. Trade-off: convenience versus detection coverage.

When should I pay for a commercial antidetect browser instead of using OSS?

When you're hitting TLS fingerprinting, need consistent fingerprints across headless and GUI modes, require multi-profile management, or when maintenance burden of keeping OSS patches current exceeds subscription cost. For scraping sites behind Cloudflare or DataDome, commercial tools with native engine patches pass where OSS leaks at the TLS layer.

Does patchright work with Playwright?

Yes. Patchright is a community fork of Playwright with stealth patches. It handles webdriver detection and some fingerprint spoofing, but shares the same TLS limitation as undetected-chromedriver — Chrome's TLS stack remains stock. For targets using ja3/ja4 fingerprinting, you'll still get flagged. Works great for lighter detection systems.


Try JustBrowser

Native Chromium antidetect browser — not extension-based. Real C++ engine patches at the canvas / WebGL / font / TLS layer, so 40+ identity parameters are genuine, not faked. REST API for Playwright, Puppeteer, Selenium. 7-day free trial, card required — then $9.99/month or $99.99/year, unlimited profiles, free team seats.

Get started → · How it differs from Multilogin / GoLogin / AdsPower

Ready to manage multiple accounts?

Seven days free, then $9.99/month — one plan, everything included.

We'd like to use Google Analytics, a Google service, to understand how our website is used. It sets two cookies in your browser and runs only if you click Accept. You can change your choice at any time with Cookie settings. Cookie Policy

Sign-in cookies and the cookie that remembers this choice are always on; the website needs them to work.

Google Analytics, a Google service, helps us understand how our website is used. It sets two cookies, _ga and _ga_TVZHQ99TZW. It is now onoff in this browser. If your browser sends a Global Privacy Control or Do Not Track signal, it stays off. Cookie Policy