Browser extensions with 8 million users collect extended AI conversations

electronic privacy invasion

In addition to ChatGPIT, Cloud, and Gemini, the extension aggregates all conversations from Copilot, Perplexity, DeepSeek, Grok, and Meta AI. Koi said full details of the captured data included:

  • Every signal that the user sends to the AI
  • every response received
  • Conversation identifier and timestamp
  • session metadata
  • Specific AI platform and model used

The executable script runs independently of VPN networking, ad blocking, or other core functionality. This means that conversation collection continues even when a user turns off VPN networking, AI protection, ad blocking, or other functions. The only way to stop harvesting is to disable the extension in browser settings or uninstall it.

Koi said he first discovered conversation harvesting in Urban VPN Proxy, a VPN routing extension that lists “AI protection” as one of its benefits. Data collection began in early July with the release of version 5.5.0.

“Anyone using ChatGate, Cloud, Gemini, or other targeted platforms while having UrbanVPN installed after July 9, 2025 should assume that those conversations are now on UrbanVPN’s servers and shared with third parties,” the company said. “Medical questions, financial details, proprietary code, personal dilemmas – all of it, sold for ‘marketing analysis purposes’.”

Following that discovery, the security firm discovered seven additional extensions with similar AI harvesting functionality. Four extensions are available in the Chrome Web Store. The other four are on the Edge add-ons page. Collectively, they have been installed more than 8 million times.

they are:

chrome store

  • Urban VPN Proxy: 6 million users
  • 1ClickVPN Proxy: 600,000 users
  • Urban Browser Guard: 40,000 users
  • Urban Ad Blocker: 10,000 users

Edge Add-on:

  • Urban VPN Proxy: 1.32 million users
  • 1ClickVPN Proxy: 36,459 users
  • Urban Browser Guard – 12,624 users
  • Urban Ad Blocker – 6,476 users

read the fine print

Extensions come with conflicting messages about how they handle bot conversations, which often contain deeply personal information about users’ physical and mental health, finances, personal relationships, and other sensitive information that can be a goldmine for marketers and data brokers. For example, Urban VPN Proxy, in the Chrome Web Store, lists “AI protection” as a benefit. It is further stated:



<a href

1 thought on “Browser extensions with 8 million users collect extended AI conversations”

  1. В Краснодаре наш интернет магазин ковров предоставляет разнообразие товаров для оформления вашего дома.
    Мир ковров онлайн
    Мы предлагаем ковры, изготовленные из шерсти, синтетики и натуральных материалов, чтобы удовлетворить любые запросы.

    Reply

Leave a Comment