Popular Chrome Extension with Over 6 Million Installs Captures User Inputs to AI Chatbots
A Chrome extension with over 6 million users has been identified as collecting and selling user conversations from various AI platforms.
A Chrome extension with over 6 million users has been identified as collecting and selling user conversations from various AI platforms.
Urban VPN Proxy, which has received Google's "Featured" badge, contains concealed code that intercepts and exfiltrates AI conversation data. While marketed as a privacy tool, it collects data from services like ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok, and Meta AI.
This discovery highlights the risks associated with browser extensions that can bypass standard security protocols. Users have unknowingly permitted the extension to monitor their interactions by installing it for VPN functionality. The data collection continues irrespective of the VPN's operational status.
The extension was featured on Google's marketplace with a high user rating, indicating a substantial breach of trust.
A Chrome extension with over 6 million users has been identified as collecting and selling user conversations from various AI platforms.
The harmful code was introduced via a silent update in July 2025, specifically in version 5.5.0. Users who installed the extension prior to this update were not notified about the new data collection capability.
Information collected includes every prompt and response sent to AI services, along with conversation identifiers, timestamps, and session metadata. The data is transmitted to Urban VPN's servers for marketing analytics purposes through BiScience, a data broker.
The threat extends beyond Urban VPN Proxy, affecting seven additional extensions from the same publisher. These extensions, under different names like 1ClickVPN Proxy and Urban Ad Blocker, utilize the same data harvesting infrastructure, impacting over 8 million users across Chrome and Microsoft Edge.
The data collection involves a four-step process where the extension injects scripts onto AI platform pages, overriding browser APIs to intercept network requests and responses. This method captures raw API data, which is processed and sent to the extension's content script using the identifier PANELOS_MESSAGE. The data is then compressed and transmitted to external servers.
The extension's purported "AI protection" feature does not affect the data harvesting process, which operates independently and continues regardless of user settings.
Based on reporting by Cyber Security News.
