AI functions are becoming more and more perfect, and many people have become accustomed to “asking AI for everything”. recently,Security researchers investigate alleged privacy extension and discover, some people are secretly collecting and selling complete conversations of users of mainstream AI platforms. Available in Microsoft Edge and other Chrome browsers, these privacy extensions target and capture conversations across multiple AI platforms, including ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok (xAI), and Meta AI.

Malicious VPN steals complete ChatGPT and Gemini conversations, over 8 million users suffer
One of the main offenders identified in the investigation was Urban VPN Proxy, an extension that has over 6 million Chrome users and holds Google’s “Featured” badge. It received a rating of 4.7 stars based on 58,500 ratings, giving the impression that it is a trustworthy app, but this study shows otherwise.

Security researchers say that on Chrome and Edge, more than 8 million users were affected by an extension that shared the same malicious code, which was also present in seven other extensions from the same publisher:
Chrome Web Store
- Urban VPN Proxy – 6 million users
- 1ClickVPN Proxy – 600,000 users
- Urban Browser Guard – 40,000 users
- Urban ad blocker – 10,000 users
Microsoft Edge add-ons:
- Urban VPN Proxy – 1.32 million users
- 1ClickVPN Proxy – 36,000 users
- Urban Browser Guard – 12,000 users
- Urban Ad Blocker – 6,400 users

These extensions will directly inject execution scripts into the web pages of the target AI platform and steal your data. This script overrides native browser functionality and allows interception of all network traffic, including requests and responses between the user and the AI platform. The script then parses the intercepted API traffic, extracting each command, AI response, timestamp, conversation ID, and session relay data. The data is then compressed and sent to Urban VPN’s servers.

Urban VPN is operated by Urban Cyber Security Inc., which is associated with data brokerage BiScience, and data from these exploits is reportedly being collected and sold for marketing analysis. This data collection is enabled by default and continues to run in the background whether you enable the VPN or not. The only way to stop it is to uninstall the extension. This feature has existed since version 5.5.0, which was released on July 9, 2025, which means that all conversations from that day onwards were leaked.

Anyone using these extensions is strongly advised to uninstall immediately and should assume that conversations on the AI platform have been compromised. This incident also raises questions about all third-party browser extensions. Unless there is a very good reason to use the extension and you are sure that the extension is safe, it is safer to uninstall it.
Source: KOCPC Chinese