Back to News
Market Impact: 0.3

Chrome, Edge privacy extensions quietly snarf AI chats

AAPLMSFTGOOGLGOOGMETA
Artificial IntelligenceCybersecurity & Data PrivacyRegulation & LegislationTechnology & Innovation
Chrome, Edge privacy extensions quietly snarf AI chats

Koi Security found four widely distributed browser extensions—Urban VPN Proxy, 1ClickVPN Proxy, Urban Browser Guard and Urban Ad Blocker—with more than 8 million installs that inject executor scripts into pages to override fetch()/XMLHttpRequest, intercept chatbot traffic from major AI platforms (ChatGPT, Claude, Gemini, Copilot, Perplexity, Grok, Meta AI, DeepSeek) and exfiltrate conversations to analytics endpoints (analytics.urban-vpn.com, stats.urban-vpn.com). The research highlights that data collection was enabled by default (no in‑extension opt‑out), a consent prompt was only added in July 2025, the extensions are affiliated with BiScience and their privacy policy indicates data is sold for marketing, and the extensions retained a Chrome Web Store Featured Badge—pointing to a policy loophole that may permit transfers under “limited use” exceptions. For institutional investors and managers the finding creates a clear operational and compliance risk—sensitive prompts, credentials or strategy discussions could have been exposed—so immediate audits and removal of these extensions are warranted and platform/regulatory scrutiny of web‑store review processes should be expected.

Analysis

Koi Security reports that four Chrome/Edge extensions — Urban VPN Proxy, 1ClickVPN Proxy, Urban Browser Guard and Urban Ad Blocker — with more than 8 million installs inject “executor” scripts that override fetch() and XMLHttpRequest to intercept chatbot traffic on at least eight AI platforms (ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok and Meta AI) and exfiltrate conversation text to analytics.urban-vpn.com and stats.urban-vpn.com. Collection was enabled by default via a hardcoded flag with no in-extension opt-out, and a consent prompt was added only in July 2025; users who installed earlier versions would not have seen the prompt. The extensions are affiliated with BiScience and Koi highlights the privacy policy permits sale of data for marketing, creating clear operational and compliance exposure for organizations that use browser-based AI tools — sensitive prompts, credentials or strategy discussions could have been captured. Chrome Web Store’s Featured Badge for Urban VPN and the identified “limited use” policy loophole imply platform review and policy interpretations may not have detected or prevented transfers to third-party data brokers. Market implications center on heightened regulatory and reputational risk for platform and browser-ecosystem stakeholders (Google/Chrome Web Store, Microsoft, Meta) and for any institutional users whose proprietary AI interactions were exposed; immediate remediation controls and anticipated regulatory scrutiny or enforcement are likely near-term outcomes. Koi’s explicit recommendation to uninstall these extensions and to assume AI conversations since July 2025 were captured frames immediate operational priorities for investors and corporate clients.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

moderately negative

Sentiment Score

-0.50

Ticker Sentiment

AAPL0.00
GOOG-0.50
GOOGL-0.50
META-0.20
MSFT-0.20

Key Decisions for Investors

  • Immediately audit corporate and personally managed devices for the four named extensions and uninstall them; assume any AI conversations since July 2025 may have been captured
  • Rotate exposed credentials and secrets, sanitize or recreate any sensitive prompts or models that may have been shared, and commission a forensic review for traffic to analytics.urban-vpn.com and stats.urban-vpn.com
  • Engage legal and compliance to assess breach/notification obligations and monitor regulatory or enforcement actions against Chrome Web Store practices and data-broker transfers, watching GOOGL/GOOG, MSFT and META for material regulatory or sentiment impacts