Close Menu

    Subscribe to Updates

    Get the latest tech news from Tallwire.

      What's Hot

      Google Cracks Down On Android Apps And Developer Accounts In 2025

      March 1, 2026

      Study Signals AI Search Shift Threatens Traditional Web Traffic Model

      March 1, 2026

      Chinese Sellers Peddling Anti-Drone Weapons On TikTok Raise Security Alarms

      March 1, 2026
      Facebook X (Twitter) Instagram
      • Tech
      • AI
      • Get In Touch
      Facebook X (Twitter) LinkedIn
      TallwireTallwire
      • Tech

        Chinese Sellers Peddling Anti-Drone Weapons On TikTok Raise Security Alarms

        March 1, 2026

        Say Goodbye to the Undersea Cable That Made the Global Internet Possible

        March 1, 2026

        Microsoft Copilot Bug Exposed “Confidential” Emails Despite Label

        February 28, 2026

        Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

        February 27, 2026

        Global Memory Shortage Set to Push Up Prices on Phones, Laptops, and More

        February 27, 2026
      • AI

        Study Signals AI Search Shift Threatens Traditional Web Traffic Model

        March 1, 2026

        AI Password Generation Poses Major Security Risk, Experts Warn

        February 28, 2026

        Microsoft Copilot Bug Exposed “Confidential” Emails Despite Label

        February 28, 2026

        AI Productivity Gains Concentrated Among High-Skilled Workers, Study Finds

        February 28, 2026

        X to Let Users Mark Posts ‘Made With AI’ as Platform Eyes Voluntary Disclosure Feature

        February 27, 2026
      • Security

        Google Cracks Down On Android Apps And Developer Accounts In 2025

        March 1, 2026

        Massive Exposed Database With Billions of Social Security Numbers Sparks Identity Theft Fears

        March 1, 2026

        Password Managers Share a Hidden Weakness

        March 1, 2026

        AI Password Generation Poses Major Security Risk, Experts Warn

        February 28, 2026

        Microsoft Copilot Bug Exposed “Confidential” Emails Despite Label

        February 28, 2026
      • Health

        Social Media Addiction Trial Draws Grieving Parents Seeking Accountability From Tech Platforms

        February 19, 2026

        Portugal’s Parliament OKs Law to Restrict Children’s Social Media Access With Parental Consent

        February 18, 2026

        Parents Paint 108 Names, Demand Snapchat Reform After Deadly Fentanyl Claims

        February 18, 2026

        UK Kids Turning to AI Chatbots and Acting on Advice at Alarming Rates

        February 16, 2026

        Landmark California Trial Sees YouTube Defend Itself, Rejects ‘Social Media’ and Addiction Claims

        February 16, 2026
      • Science

        Astronomers Confirm Discovery Of Galaxy Nearly Entirely Composed Of Dark Matter

        March 1, 2026

        Microsoft Claims 100 Percent Renewable Energy Match Across Global Electricity Use

        February 28, 2026

        Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

        February 27, 2026

        Large Hadron Collider Enters Third Shutdown For Major Upgrade

        February 26, 2026

        Google Phases Out Android’s Built-In Weather App, Replacing It With Search-Based Forecasts

        February 25, 2026
      • Tech

        Sam Altman Says ‘AI Washing’ Is Being Used to Mask Corporate Layoffs

        February 28, 2026

        Zuckerberg Testifies In Landmark Trial Over Alleged Teen Social Media Harms

        February 23, 2026

        Gay Tech Networks Under Spotlight In Silicon Valley Culture Debate

        February 23, 2026

        Google Co-Founder’s Epstein Contacts Reignite Scrutiny of Elite Tech Circles

        February 7, 2026

        Bill Gates Denies “Absolutely Absurd” Claims in Newly Released Epstein Files

        February 6, 2026
      TallwireTallwire
      Home»Tech»Featured Chrome Browser Extension Caught Intercepting Millions Of Users’ AI Chats
      Tech

      Featured Chrome Browser Extension Caught Intercepting Millions Of Users’ AI Chats

      3 Mins Read
      Facebook Twitter Pinterest LinkedIn Tumblr Email
      Featured Chrome Browser Extension Caught Intercepting Millions Of Users’ AI Chats
      Featured Chrome Browser Extension Caught Intercepting Millions Of Users’ AI Chats
      Share
      Facebook Twitter LinkedIn Pinterest Email

      A widely used Google Chrome extension with a “Featured” badge and over six million installations has been discovered secretly harvesting AI chat data from users of major chatbot platforms such as ChatGPT, Claude, Gemini, Copilot, Grok, and Perplexity, rerouting every prompt and response through hidden code to remote servers under the guise of a VPN service; the extension, Urban VPN Proxy, updated in mid-2025 to embed this data capture functionality by default, sniffing conversation text, timestamps, and session metadata and funneling it to external analytics domains despite claiming the practice was limited to anonymized marketing use, raising sharp concerns about how trusted labels and auto-update mechanisms enable persistent and opaque data collection at scale, and underscoring broader risks tied to browser extension permissions and marketplace oversight.

      Source: Hacker News

      Key Takeaways

      • A “Featured” Chrome extension trusted by millions was covertly modified to intercept and exfiltrate AI chatbot data without clear user consent.

      • Browser extensions can gain deep access to web activity and auto-update mechanisms make silent deployment of harmful code easier.

      • Security professionals warn that both individual users and enterprise environments must reevaluate extension governance and treat these tools as part of the broader attack surface.

      In-Depth

      In a troubling development that underscores the growing cybersecurity gaps in widely trusted platforms, a Google Chrome browser extension that millions of users assume to be secure has been revealed to be quietly collecting AI chat conversations. Urban VPN Proxy, a free VPN touted for privacy and protection, was granted a “Featured” badge in the Chrome Web Store—a designation many users interpret as a de facto endorsement of quality and safety. However, an update pushed in July 2025 added stealthy code that hijacks every prompt and response entered into major AI chatbot services and funnels them to remote servers controlled by third parties. This wasn’t a blatant hack from outside the browser ecosystem; it was an update users accepted through Chrome’s automatic update mechanism, completely under the radar.

      From a conservative perspective emphasizing personal responsibility and market accountability, this incident highlights the danger of unchecked reliance on centralized platforms and internal vetting badges. Users are right to expect that featured products meet objective standards, but marketplaces like Chrome’s Web Store are fundamentally unable to police every extension’s future behavior once installed. Permissive permission requests and broad API access give extensions deep hooks into sensitive user activity; in this case, that meant access to people’s thoughts, work product, and search behavior on AI platforms—a vastly underappreciated data set.

      Security experts also warn that extensions are no longer peripheral add-ons; they are potential entry points for data exfiltration and supply-chain attacks. Because Chrome and other browsers push updates automatically, once a developer account is compromised or an update with malicious intent is published, millions of users install it passively. Businesses that allow employees to install extensions without oversight are exposing corporate networks and cloud credentials to similar risks. The broader pattern seen in recent months, including supply-chain campaigns turning trusted tools into spyware, suggests this is not an isolated flaw but a systemic vulnerability in the extension ecosystem.

      Practical steps for users and organizations include auditing installed extensions, limiting extension permissions aggressively, and enforcing allow lists rather than broad install freedom. The Urban VPN Proxy case should serve as a wake-up call: trust badges aren’t guarantees, and personal or corporate data security requires active, informed management of even seemingly benign browser add-ons.

      Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
      Previous ArticleFCC Warns Radio Stations After Hackers Hijack Airwaves, Send Fake Alerts And Obscenities
      Next Article Fed Chair Powell Asserts AI Spending Isn’t a Bubble — Despite Rising Warnings

      Related Posts

      Chinese Sellers Peddling Anti-Drone Weapons On TikTok Raise Security Alarms

      March 1, 2026

      Say Goodbye to the Undersea Cable That Made the Global Internet Possible

      March 1, 2026

      Microsoft Copilot Bug Exposed “Confidential” Emails Despite Label

      February 28, 2026

      Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

      February 27, 2026
      Add A Comment
      Leave A Reply Cancel Reply

      Editors Picks

      Chinese Sellers Peddling Anti-Drone Weapons On TikTok Raise Security Alarms

      March 1, 2026

      Say Goodbye to the Undersea Cable That Made the Global Internet Possible

      March 1, 2026

      Microsoft Copilot Bug Exposed “Confidential” Emails Despite Label

      February 28, 2026

      Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

      February 27, 2026
      Popular Topics
      Sundar Pichai Tim Cook Ransomware Series B Series A spotlight Robotics Quantum computing Samsung Qualcomm Tesla Cybertruck SpaceX picks Satya Nadella Sam Altman Tesla trending Taiwan Tech UAE Tech Startup
      Major Tech Companies
      • Apple News
      • Google News
      • Meta News
      • Microsoft News
      • Amazon News
      • Samsung News
      • Nvidia News
      • OpenAI News
      • Tesla News
      • AMD News
      • Anthropic News
      • Elbit News
      AI & Emerging Tech
      • AI Regulation News
      • AI Safety News
      • AI Adoption
      • Quantum Computing News
      • Robotics News
      Key People
      • Sam Altman News
      • Jensen Huang News
      • Elon Musk News
      • Mark Zuckerberg News
      • Sundar Pichai News
      • Tim Cook News
      • Satya Nadella News
      • Mustafa Suleyman News
      Global Tech & Policy
      • Israel Tech News
      • India Tech News
      • Taiwan Tech News
      • UAE Tech News
      Startups & Emerging Tech
      • Series A News
      • Series B News
      • Startup News
      Tallwire
      Facebook X (Twitter) LinkedIn Threads Instagram RSS
      • Tech
      • Entertainment
      • Business
      • Government
      • Academia
      • Transportation
      • Legal
      • Press Kit
      © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

      Type above and press Enter to search. Press Esc to cancel.