Home
News

Millions at Risk! Chrome Extension Secretly Harvested ChatGPT, Gemini Chats

Google Chrome’s extension ecosystem is one of the reasons the browser has stayed dominant for so long. With a few clicks, you can add tools that promise better privacy, faster browsing, or extra security. But that same convenience can also work against users when an extension doesn’t behave the way it claims.

This Popular Chrome Extension Was Quietly Collecting AI Chatbot Chats

That’s exactly what security researchers are now warning about after taking a closer look at a widely used Chrome extension called Urban VPN Proxy.

A “Privacy” Extension With Millions of Users

Urban VPN Proxy isn’t some obscure add-on buried deep in the Chrome Web Store. It has more than six million users, carries Google’s “Featured” badge, and holds an average rating of around 4.7 stars. On the surface, it looks like a safe, trusted VPN-style extension designed to protect your online activity.

According to findings from security researchers at Koi, however, the extension was doing something very different in the background. It was capturing conversations from popular AI chatbots while users interacted with them in their browsers.

Which AI Platforms Were Affected

The researchers say Urban VPN Proxy targeted conversations across at least 10 AI platforms. That list includes ChatGPT, Claude, Google Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok from xAI, and Meta AI.

In practice, this means prompts you typed and responses you received could be intercepted while the extension was active. For users who rely on AI tools for work, research, or personal use, that’s a serious privacy concern.

How the Extension Collected Chat Data

According to the research, Urban VPN Proxy used separate scripts for each supported AI platform. These scripts were injected directly into chatbot webpages, allowing the extension to read conversations as they happened.

The data collected reportedly included user prompts, AI responses, timestamps, and session-related metadata. Researchers noted that there was no simple way to opt out of this behavior. The only reliable way to stop the data collection was to uninstall the extension entirely.

When This Behavior Started

The interception reportedly began with version 5.5.0 of Urban VPN Proxy, which was released earlier this year in July.

Because Chrome extensions update automatically by default, most users had no visible indication that anything had changed. The extension continued to function normally, while quietly expanding what it was collecting behind the scenes.

As a result, many users were unaware that their AI chatbot conversations were being accessed at all.

The Problem Goes Beyond One Extension

Urban VPN Proxy wasn’t the only extension flagged by researchers. The same data-collection code was also found in several other Chrome extensions from the same developer.

These reportedly include tools like 1ClickVPNProxy, Urban Browser Guard, and Urban Ad Blocker. That suggests the issue may be broader than a single app, especially for users who install multiple extensions from the same publisher.

Who’s Behind Urban VPN Proxy

Urban VPN Proxy is owned by Urban Cyber Security Inc, which is reportedly affiliated with data broker BiScience.

According to reports referenced by researchers, the collected data is being sold to marketing and analytics firms. While data brokerage itself isn’t new, it directly clashes with how a VPN-branded privacy extension is typically marketed to users.

Why This Is a Wake-Up Call for Chrome Users

This situation highlights an uncomfortable reality. High ratings, large install numbers, and even official badges don’t always mean an extension is safe in the long term. An update can change how an extension behaves, and most users won’t notice unless they’re actively monitoring it.

If you regularly use AI chatbots, especially for sensitive or work-related conversations, it’s worth reviewing which extensions you’ve installed and whether you still need them. In some cases, removing a “helpful” add-on may be the safest option.

Best Mobiles in India

Notifications
Settings
Clear Notifications
Notifications
Use the toggle to switch on notifications
  • Block for 8 hours
  • Block for 12 hours
  • Block for 24 hours
  • Don't block
Gender
Select your Gender
  • Male
  • Female
  • Others
Age
Select your Age Range
  • Under 18
  • 18 to 25
  • 26 to 35
  • 36 to 45
  • 45 to 55
  • 55+
X