By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats
Computing

Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats

News Room
Last updated: 2025/12/15 at 1:32 PM
News Room Published 15 December 2025
Share
Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats
SHARE

A Google Chrome extension with a “Featured” badge and six million users has been observed silently gathering every prompt entered by users into artificial intelligence (AI)-powered chatbots like OpenAI ChatGPT, Anthropic Claude, Microsoft Copilot, DeepSeek, Google Gemini, xAI Grok, Meta AI, and Perplexity.

The extension in question is Urban VPN Proxy, which has a 4.7 rating on the Google Chrome Web Store. It’s advertised as the “best secured Free VPN access to any website, and unblock content.” Its developer is a Delaware-based company named Urban Cyber Security Inc. On the Microsoft Edge Add-ons marketplace, it has 1.3 million installations.

Despite claiming that it allows users to “protect your online identity, stay protected, and hide your IP,” the extension was updated on July 9, 2025, when version 5.5.0 was released with the AI data harvesting enabled by default using hard-coded settings.

Specifically, this is achieved by means of a tailored executor JavaScript that’s triggered for each of the AI chatbots (i.e., chatgpt.js, claude.js, gemini.js) to intercept and gather the conversations every time a user who has installed the extension visits any of the targeted platforms.

Once the script is injected, it overrides the browser APIs used to handle network requests – fetch() and XMLHttpRequest() – to make sure that every request is first routed through the extension’s code so as to capture the conversation data, including users’ prompts and the chatbot’s responses, and exfiltrate them to two remote servers (“analytics.urban-vpn[.]com” and “stats.urban-vpn[.]com”).

Cybersecurity

The exact list of data captured by the extension is as follows –

  • Prompts entered by the user
  • Chatbot responses
  • Conversation identifiers and timestamps
  • Session metadata
  • AI platform and model used

“Chrome and Edge extensions auto-update by default,” Koi Security’s Idan Dardikman said in a report published today. “Users who installed Urban VPN for its stated purpose – VPN functionality – woke up one day with new code silently harvesting their AI conversations.”

It’s worth mentioning that Urban VPN’s updated privacy policy, as of June 25, 2025, mentions that it collects this data to enhance Safe Browsing and for marketing analytics purposes, and that any other secondary use of the gathered AI prompts will be carried out on de-identified and anonymized data –

As part of the Browsing Data, we will collect the prompts and outputs quired [sic] by the End-User or generated by the AI chat provider, as applicable. Meaning, we are only interested in the AI prompt and the results of your interaction with the chat AI.

Due to the nature of the data involved in AI prompts, some sensitive personal information may be processed. However, the purpose of this processing is not to collect personal or identifiable data, we cannot fully guarantee the removal of all sensitive or personal information, we implement measures to filter out or eliminate any identifiers or personal data you may submit through the prompts and to de-identify and aggregate the data.

One of the third-parties it shares “Web Browsing Data” with is an affiliated ad intelligence and brand monitoring firm named BIScience. The company uses the raw (not anonymized) data to create insights that are “commercially used and shared with Business Partners,” the VPN software maker notes.

It’s worth noting BiScience, which also happens to own Urban Cyber Security Inc., was called out by an anonymous researcher earlier this January for collecting users’ browsing history, or clickstream data, as it’s called, under misleading privacy policy disclosures.

The company is alleged to provide a software development kit (SDK) to partner third-party extension developers to collect clickstream data from users, which is transmitted to the sclpfybn[.]com and other endpoints under its control.

“BIScience and partners take advantage of loopholes in the Chrome Web Store policies, mainly exceptions listed in the Limited Use policy, which are the ‘approved use cases,'” the researcher noted, adding they “develop user-facing features that allegedly require access to browsing history, to claim the ‘necessary to providing or improving your single purpose’ exception.”

On the extension listing page, Urban VPN also highlights an “AI protection” feature, which it says checks prompts for personal data, chatbot responses for suspicious or unsafe links, and displays a warning before users submit their prompts or click on them.

While this monitoring is framed as preventing users from accidentally sharing any personal information, what the developers fail to mention is that the data collection happens regardless of whether the feature is enabled.

“The protection feature shows occasional warnings about sharing sensitive data with AI companies,” Dardikman said. “The harvesting feature sends that exact sensitive data – and everything else – to Urban VPN’s own servers, where it’s sold to advertisers. The extension warns you about sharing your email with ChatGPT while simultaneously exfiltrating your entire conversation to a data broker.”

Cybersecurity

Koi Security said it observed identical AI harvesting functionality in three other unique extensions from the same publisher across Chrome and Microsoft Edge, taking its total install base to over eight million –

  • 1ClickVPN Proxy
  • Urban Browser Guard
  • Urban Ad Blocker

All these extensions, with the exception of Urban Ad Blocker for Edge, carry the “Featured” badge, giving users an impression that they follow the platform’s “best practices and meet a high standard of user experience and design.”

“These badges signal to users that the extensions have been reviewed and meet platform quality standards,” Dardikman pointed out. “For many users, a Featured badge is the difference between installing an extension and passing it by – it’s an implicit endorsement from Google and Microsoft.”

The findings once again demonstrate how trust associated with extension marketplaces can be abused to amass sensitive data at scale, especially at a time when users are increasingly sharing deeply personal information, getting advice, and discussing emotions with AI chatbots.

The Hacker News has reached out to both Google and Microsoft for comment, and we will update the story if we hear back.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Sony Inzone M9 II 27-inch 4K gaming monitor: 8 at Amazon Sony Inzone M9 II 27-inch 4K gaming monitor: $698 at Amazon
Next Article Google AI summaries are ruining the livelihoods of recipe writers: ‘It’s an extinction event’ Google AI summaries are ruining the livelihoods of recipe writers: ‘It’s an extinction event’
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Apple’s iPhone Fold May Skip Face ID; Display And Camera Specs Leak
Apple’s iPhone Fold May Skip Face ID; Display And Camera Specs Leak
Mobile
UK government to ask Apple, Google to block nudity online without age verification, report says
UK government to ask Apple, Google to block nudity online without age verification, report says
News
Black Myth: Wukong wins Best Action Game at TGA 2024, misses out on Game of the Year · TechNode
Black Myth: Wukong wins Best Action Game at TGA 2024, misses out on Game of the Year · TechNode
Computing
New in iOS 26.3: Android transfer settings, third-party notification forwarding
New in iOS 26.3: Android transfer settings, third-party notification forwarding
News

You Might also Like

Black Myth: Wukong wins Best Action Game at TGA 2024, misses out on Game of the Year · TechNode
Computing

Black Myth: Wukong wins Best Action Game at TGA 2024, misses out on Game of the Year · TechNode

1 Min Read
China’s Instagram-like app Xiaohongshu expected to top  billion profit ahead of potential IPO · TechNode
Computing

China’s Instagram-like app Xiaohongshu expected to top $1 billion profit ahead of potential IPO · TechNode

2 Min Read
Gobi Partners Announces Techxila Fund II and Signs MOU with Bank of PunjabGobi Partners Announces Techxila Fund II and Signs MOU with Bank of Punjab to Drive Economic Cooperation · TechNode
Computing

Gobi Partners Announces Techxila Fund II and Signs MOU with Bank of PunjabGobi Partners Announces Techxila Fund II and Signs MOU with Bank of Punjab to Drive Economic Cooperation · TechNode

6 Min Read
Xiaomi’s EV business ramps up hiring in preparation for overseas sales · TechNode
Computing

Xiaomi’s EV business ramps up hiring in preparation for overseas sales · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?