
"Browser extensions that promise privacy are found to be selling AI conversations from millions of users. Security researchers at Koi Security discovered that popular VPN and ad blocker extensions are secretly intercepting all conversations with ChatGPT, Claude, and Gemini and reselling them to data brokers. Security researcher Idan Dardikman discovered the problem after wondering if anyone could read his private conversations with AI assistants."
"The extension intercepts conversations from ten AI platforms, including ChatGPT, Claude, Gemini, Microsoft Copilot, and Perplexity. For each platform, the extension uses a special script that captures all prompts and responses before they even appear on the screen. Users cannot disable this; only removing the extension stops the spying. Selling under the guise of protection Urban VPN presents AI monitoring as a security feature. The extension is supposed to warn users when they share personal data with ChatGPT."
"The data goes to Urban Cyber Security Inc., affiliated with BiScience, a data broker. The collection practices are not new: security researchers had previously targeted BiScience for selling browsing history. The extensions added the AI interception in version 5.5.0 on July 9, 2025. Users who installed the extension before that date received a silent update without a new consent request. Anyone who has used ChatGPT, Claude, or Gemini with Urban VPN since July should assume that those conversations have been sold."
Koi Security researchers uncovered that popular VPN and ad-blocker browser extensions intercepted and resold AI assistant conversations from millions of users. Urban VPN Proxy, a Chrome extension with 6 million users and a "Featured" badge from Google, injected scripts that captured prompts and responses from ten AI platforms, including ChatGPT, Claude, Gemini, Microsoft Copilot, and Perplexity, before content appeared on screen. Captured conversations were transmitted to Urban Cyber Security Inc., affiliated with data broker BiScience. The AI interception was added in version 5.5.0 on July 9, 2025 via a silent update, exposing conversations from users who used the extensions since then.
Read at Techzine Global
Unable to calculate read time
Collection
[
|
...
]