Cybersecurity specialists caution that this browser add-on is selling your ChatGPT conversations

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

A cybersecurity firm has asserted that various web browser extensions are covertly recording and monetizing users’ interactions with AI chatbots.

Koi, a company dedicated to safeguarding against extension-based cyber threats, unveiled a report alleging that Urban VPN Proxy—a widely-used VPN extension compatible with Google Chrome and Microsoft Edge—harbors a clandestine function that captures user dialogues on AI platforms such as ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok, and Meta AI. According to Koi, this nefarious capability was surreptitiously integrated in July.

The report details that when users are equipped with the extension and access any of the aforementioned platforms, an “executor” script is injected into the webpage.

Consequently, every network request and response traverses the extension’s code first, thereby granting it visibility over all messages exchanged by users as well as those generated by the AI. Once harvested, this data is dispatched to external servers associated with the extension.

Urban VPN Proxy was not the sole extension singled out by Koi for its alleged AI data harvesting conduct. The firm further identified multiple extensions originating from the same developer that exhibit similar malicious code:

Google Chrome Extensions:

  • Urban VPN Proxy – 6,000,000 users
  • 1ClickVPN Proxy – 600,000 users
  • Urban Browser Guard – 40,000 users
  • Urban Ad Blocker – 10,000 users

Microsoft Edge Extensions:

  • Urban VPN Proxy – 1,323,622 users
  • 1ClickVPN Proxy – 36,459 users
  • Urban Browser Guard – 12,624 users
  • Urban Ad Blocker – 6,476 users

In total, Koi estimates that upwards of 8 million users have installed these extensions. The organization behind them, Urban Cyber Security, is reportedly linked to BiScience, a company engaged in data brokering.

Significantly, Koi lacks definitive evidence regarding the fate of the logged conversations, yet Urban VPN’s privacy policy reveals that it intends to “collect the prompts and outputs queried by the End-User or generated by the AI chat provider,” and further notes that “we also disclose the AI prompts for marketing analytics purposes.”

The Koi team cautioned: “If you have any of these extensions installed, uninstall them immediately. Assume that any AI conversations you’ve engaged in since July 2025 have been recorded and disseminated to third parties.”

On December 18, Urban VPN issued a blog entry entitled “Setting the Record Straight: How Urban VPN’s AI Protection Feature Actually Works,” dismissing several widely circulated claims as unfounded.

The organization contended that dialogues between users and AI chatbots are processed solely if a user expressly consents to the extension’s “AI Protection” feature.

Partial view of a keyboard with a highlighted blue key labeled AI featuring a hand icon, set against a black background.

Moreover, Urban VPN asserted that it does not collect “raw personal or sensitive information” from chatbot interactions, insisting that such data is meticulously filtered and purged of personal identifiers.

However, the organization did not refute that it targets content from specific AI platforms or that it sells said content to clients.

Looking ahead, Urban VPN has indicated plans to reevaluate its user experience language to “mitigate confusion” and clarify the opt-in process.

Source link: Thestar.com.my.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

RS Web Solutions

We provide the best tutorials, reviews, and recommendations on all technology and open-source web-related topics. Surf our site to extend your knowledge base on the latest web trends.
Share the Love
Related News Worth Reading