A popular Google Chrome extension called Urban VPN Proxy has been secretly collecting user prompts and conversations from AI chatbots, including ChatGPT and Google Gemini, and exfiltrating this data to remote servers. Despite its marketing as a secure VPN, the extension was updated to enable default AI data harvesting, raising concerns about privacy and data misuse. #UrbanVPNProxy #AIDataHarvesting
Keypoints
- The Urban VPN Proxy extension has over six million users and offers VPN services while secretly collecting AI Chatbot conversations.
- The extension injects JavaScript to intercept and capture user prompts, responses, and session data from AI platforms.
- Collected data is sent to remote servers and shared with third-party companies like BIScience for commercial insights.
- The extensionโs โAI protectionโ feature is misleading, as data collection occurs regardless of whether the feature is enabled.
- Multiple extensions from the same publisher also contain AI harvesting functionalities, exploiting platform badges to gain user trust.
Read More: https://thehackernews.com/2025/12/featured-chrome-browser-extension.html