Browser extensions with 8 million users caught secretly harvesting AI conversations

Reviewed byNidhi Govil

11 Sources

Share

Popular browser extensions marketed as VPNs and ad blockers are intercepting and selling complete AI chatbot conversations from millions of users. Cybersecurity firm Koi discovered eight extensions, including Urban VPN Proxy with 6 million installs, that capture every prompt and response from platforms like ChatGPT, Claude, and Gemini. The data is transmitted to third-party marketing firms, with no way to disable collection except complete uninstallation.

Browser Extensions Collecting AI Conversations from Millions

Browser extensions installed more than 8 million times are secretly harvesting user conversations from AI chat platforms and selling them for marketing purposes, according to cybersecurity firm Koi Security

1

. The eight extensions, discovered by Koi, remained available in both Google's Chrome Web Store and Microsoft Edge add-ons stores as of late Tuesday night. Seven carried "Featured" badgesโ€”official endorsements suggesting the software met quality and security standards

3

. The free extensions promise functions like VPN routing and ad blocking while assuring users their data remains anonymous and isn't shared beyond described uses.

How Data Harvesting Works Through Executor Scripts

An examination of the extensions' underlying code reveals a sophisticated interception mechanism. Each extension contains eight executor scripts, uniquely designed for ChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek, Grok, and Meta AI

2

. These scripts inject themselves into webpages whenever users visit any of the targeted AI chat platforms. The scripts override built-in browser functions for making network requests and receiving responsesโ€”specifically fetch() and XMLHttpRequest APIs

3

. "By overriding the [browser APIs], the extension inserts itself into that flow and captures a copy of everything before the page even displays it," explained Koi CTO Idan Dardikman

1

. All interaction between the browser and AI chatbot interactions is routed through the executor script rather than legitimate browser APIs, allowing complete capture of AI conversations in raw form.

Source: TechSpot

Source: TechSpot

Urban VPN Proxy Leading the Data Collection Effort

Koi first discovered the conversation harvesting in Urban VPN Proxy, which lists "AI protection" as one of its advertised benefits

1

. The popular Chrome extensions began collecting conversation logs in early July with version 5.5.0. Urban VPN Proxy alone accounts for 6 million users on Chrome and 1.32 million on Microsoft Edge

1

.

Source: MakeUseOf

Source: MakeUseOf

The extension captures every prompt users send, every response received, conversation identifiers and timestamps, session metadata, and the specific AI platform and model used

1

. "Anyone who used ChatGPT, Claude, Gemini, or the other targeted platforms while Urban VPN was installed after July 9, 2025 should assume those conversations are now on Urban VPN's servers and have been shared with third parties," Koi warned

1

.

Privacy Risks and Marketing Analytics Purposes

The data harvesting presents significant privacy risks as AI conversations often contain deeply personal information about users' physical and mental health, finances, personal relationships, and other sensitive details

1

. Medical questions, financial details, proprietary code, and personal dilemmas are all captured and sold for marketing analytics purposes

1

.

Source: The Register

Source: The Register

The executor script runs independently from VPN networking, ad blocking, or other core functionality, meaning that even when users toggle off these features, stealing AI chat logs continues

1

. The only way to stop data collection is to disable the extension in browser settings or uninstall it completely

2

.

BiScience Connection and Third-Party Data Sharing

All eight extensions trace back to Urban Cyber Security, which advertises its apps as being used by 100 million people worldwide. The privacy policy identifies BiScience (also listed as B.I Science) as an affiliated partner that "uses this raw data and creates insights which are commercially used and shared with Business Partners". BiScience's own policy states its services "transform enormous volumes of digital signals into clear, actionable market intelligence". The extensions compress captured data and send it to endpoints at analytics.urban-vpn.com and stats.urban-vpn.com

3

. While Urban VPN does disclose AI data collection in its 6,000-word privacy policy, stating it will "collect the prompts and outputs queried by the End-User" and "disclose the AI prompts for marketing analytics purposes," this disclosure contradicts Chrome Web Store claims that data isn't sold to third parties.

Complete List of Affected Extensions

Following the Urban VPN Proxy discovery, Koi Security uncovered seven additional extensions with identical AI harvesting functionality

1

. On Chrome Web Store: Urban VPN Proxy (6 million users), 1ClickVPN Proxy (600,000 users), Urban Browser Guard (40,000 users), and Urban Ad Blocker (10,000 users). On Microsoft Edge: Urban VPN Proxy (1.32 million users), 1ClickVPN Proxy (36,459 users), Urban Browser Guard (12,624 users), and Urban Ad Blocker (6,476 users)

1

. All extensions have since been removed from Chrome Web Store but remain on Edge Store, where 1ClickVPN Proxy is still listed as "Featured"

2

.

Questions About Platform Review Standards

The incident raises concerns about how Google and Microsoft review extensions before granting Featured status. "This means a human at Google reviewed Urban VPN Proxy and concluded it met their standards," Dardikman noted. "Either the review didn't examine the code that harvests conversations from Google's own AI product (Gemini), or it did and didn't consider this a problem"

2

. Chrome Web Store policies explicitly prohibit transferring or selling user data to third-party data brokers like BiScience

3

. However, a loophole in Google's Limited Use policy allows data transfer for limited scenarios that bad actors exploit by falsely claiming exceptions through user consent or security features

3

. Users who installed Urban VPN prior to July 2025 never saw any consent prompt, which was added via silent update

3

.

What Users Should Watch For

Cybersecurity experts warn this case exemplifies risks of free tools. "The Urban VPN story is a classic example of what happens when people put blind trust in 'free' tools. If you don't know how a tool makes money, assume it's monetising your data," said Sam Soares, Chief Revenue Officer at CultureAI

5

. Koi recommends anyone with these extensions installed should uninstall them immediately and assume any AI conversations since July 2025 have been captured and shared with third parties

2

. Users concerned about collected data can sign up for data removal services that contact data brokers and submit deletion requests

5

. This incident underscores the need to thoroughly investigate browser extensions before installation and be mindful of what information gets shared with AI tools, as combining questionable AI company data practices with malicious browser extensions creates compounding privacy risks

5

.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Donโ€™t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

ยฉ 2026 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo