Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    AI Safety Researcher Resigns, Warns ‘World Is in Peril’ Amid Broader Industry Concerns

    February 15, 2026

    Amazon’s Eero Signal Introduces Cellular Backup for Home Internet Outages

    February 15, 2026

    Microsoft Warns Hackers Are Exploiting Critical Zero-Day Bugs Targeting Windows, Office Users

    February 15, 2026
    Facebook X (Twitter) Instagram
    • Tech
    • AI News
    • Get In Touch
    Facebook X (Twitter) LinkedIn
    TallwireTallwire
    • Tech

      Amazon’s Eero Signal Introduces Cellular Backup for Home Internet Outages

      February 15, 2026

      AI Safety Researcher Resigns, Warns ‘World Is in Peril’ Amid Broader Industry Concerns

      February 15, 2026

      OpenAI Disbands Mission Alignment Team Amid Internal Restructuring And Safety Concerns

      February 14, 2026

      Startup’s New Chip Tech Aims to Make Luxury Goods Harder to Fake

      February 14, 2026

      Microsoft Exchange Online’s Aggressive Filters Mistake Legitimate Emails for Phishing

      February 13, 2026
    • AI News

      Amazon’s Eero Signal Introduces Cellular Backup for Home Internet Outages

      February 15, 2026

      AI Safety Researcher Resigns, Warns ‘World Is in Peril’ Amid Broader Industry Concerns

      February 15, 2026

      Amazon Eyes Marketplace to Let Publishers Sell Content to AI Firms

      February 15, 2026

      OpenAI Disbands Mission Alignment Team Amid Internal Restructuring And Safety Concerns

      February 14, 2026

      Startup’s New Chip Tech Aims to Make Luxury Goods Harder to Fake

      February 14, 2026
    • Security

      AI Safety Researcher Resigns, Warns ‘World Is in Peril’ Amid Broader Industry Concerns

      February 15, 2026

      Microsoft Warns Hackers Are Exploiting Critical Zero-Day Bugs Targeting Windows, Office Users

      February 15, 2026

      Microsoft Exchange Online’s Aggressive Filters Mistake Legitimate Emails for Phishing

      February 13, 2026

      China’s Salt Typhoon Hackers Penetrate Norwegian Networks in Espionage Push

      February 12, 2026

      Reality Losing the Deepfake War as C2PA Labels Falter

      February 11, 2026
    • Health

      Amazon Pharmacy Rolls Out Same-Day Prescription Delivery To 4,500 U.S. Cities

      February 14, 2026

      AI Advances Aim to Bridge Labor Gaps in Rare Disease Treatment

      February 12, 2026

      Boeing and Israel’s Technion Forge Clean Fuel Partnership to Reduce Aviation Carbon Footprints

      February 11, 2026

      OpenAI’s Drug Royalties Model Draws Skepticism as Unworkable in Biotech Reality

      February 10, 2026

      New AI Health App From Fitbit Founders Aims To Transform Family Care

      February 9, 2026
    • Science

      XAI Publicly Unveils Elon Musk’s Interplanetary AI Vision In Rare All-Hands Release

      February 14, 2026

      Elon Musk Shifts SpaceX Priority From Mars Colonization to Building a Moon City

      February 14, 2026

      NASA Artemis II Spacesuit Mobility Concerns Ahead Of Historic Mission

      February 13, 2026

      AI Agents Build Their Own MMO Playground After Moltbook Ignites Agent-Only Web Communities

      February 12, 2026

      AI Advances Aim to Bridge Labor Gaps in Rare Disease Treatment

      February 12, 2026
    • People

      Google Co-Founder’s Epstein Contacts Reignite Scrutiny of Elite Tech Circles

      February 7, 2026

      Bill Gates Denies “Absolutely Absurd” Claims in Newly Released Epstein Files

      February 6, 2026

      Informant Claims Epstein Employed Personal Hacker With Zero-Day Skills

      February 5, 2026

      Starlink Becomes Critical Internet Lifeline Amid Iran Protest Crackdown

      January 25, 2026

      Musk Pledges to Open-Source X’s Recommendation Algorithm, Promising Transparency

      January 21, 2026
    TallwireTallwire
    Home»Tech»Featured Chrome Browser Extension Caught Intercepting Millions Of Users’ AI Chats
    Tech

    Featured Chrome Browser Extension Caught Intercepting Millions Of Users’ AI Chats

    3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Featured Chrome Browser Extension Caught Intercepting Millions Of Users’ AI Chats
    Featured Chrome Browser Extension Caught Intercepting Millions Of Users’ AI Chats
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A widely used Google Chrome extension with a “Featured” badge and over six million installations has been discovered secretly harvesting AI chat data from users of major chatbot platforms such as ChatGPT, Claude, Gemini, Copilot, Grok, and Perplexity, rerouting every prompt and response through hidden code to remote servers under the guise of a VPN service; the extension, Urban VPN Proxy, updated in mid-2025 to embed this data capture functionality by default, sniffing conversation text, timestamps, and session metadata and funneling it to external analytics domains despite claiming the practice was limited to anonymized marketing use, raising sharp concerns about how trusted labels and auto-update mechanisms enable persistent and opaque data collection at scale, and underscoring broader risks tied to browser extension permissions and marketplace oversight.

    Source: Hacker News

    Key Takeaways

    • A “Featured” Chrome extension trusted by millions was covertly modified to intercept and exfiltrate AI chatbot data without clear user consent.

    • Browser extensions can gain deep access to web activity and auto-update mechanisms make silent deployment of harmful code easier.

    • Security professionals warn that both individual users and enterprise environments must reevaluate extension governance and treat these tools as part of the broader attack surface.

    In-Depth

    In a troubling development that underscores the growing cybersecurity gaps in widely trusted platforms, a Google Chrome browser extension that millions of users assume to be secure has been revealed to be quietly collecting AI chat conversations. Urban VPN Proxy, a free VPN touted for privacy and protection, was granted a “Featured” badge in the Chrome Web Store—a designation many users interpret as a de facto endorsement of quality and safety. However, an update pushed in July 2025 added stealthy code that hijacks every prompt and response entered into major AI chatbot services and funnels them to remote servers controlled by third parties. This wasn’t a blatant hack from outside the browser ecosystem; it was an update users accepted through Chrome’s automatic update mechanism, completely under the radar.

    From a conservative perspective emphasizing personal responsibility and market accountability, this incident highlights the danger of unchecked reliance on centralized platforms and internal vetting badges. Users are right to expect that featured products meet objective standards, but marketplaces like Chrome’s Web Store are fundamentally unable to police every extension’s future behavior once installed. Permissive permission requests and broad API access give extensions deep hooks into sensitive user activity; in this case, that meant access to people’s thoughts, work product, and search behavior on AI platforms—a vastly underappreciated data set.

    Security experts also warn that extensions are no longer peripheral add-ons; they are potential entry points for data exfiltration and supply-chain attacks. Because Chrome and other browsers push updates automatically, once a developer account is compromised or an update with malicious intent is published, millions of users install it passively. Businesses that allow employees to install extensions without oversight are exposing corporate networks and cloud credentials to similar risks. The broader pattern seen in recent months, including supply-chain campaigns turning trusted tools into spyware, suggests this is not an isolated flaw but a systemic vulnerability in the extension ecosystem.

    Practical steps for users and organizations include auditing installed extensions, limiting extension permissions aggressively, and enforcing allow lists rather than broad install freedom. The Urban VPN Proxy case should serve as a wake-up call: trust badges aren’t guarantees, and personal or corporate data security requires active, informed management of even seemingly benign browser add-ons.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleFCC Warns Radio Stations After Hackers Hijack Airwaves, Send Fake Alerts And Obscenities
    Next Article Fed Chair Powell Asserts AI Spending Isn’t a Bubble — Despite Rising Warnings

    Related Posts

    Amazon’s Eero Signal Introduces Cellular Backup for Home Internet Outages

    February 15, 2026

    AI Safety Researcher Resigns, Warns ‘World Is in Peril’ Amid Broader Industry Concerns

    February 15, 2026

    OpenAI Disbands Mission Alignment Team Amid Internal Restructuring And Safety Concerns

    February 14, 2026

    Startup’s New Chip Tech Aims to Make Luxury Goods Harder to Fake

    February 14, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Amazon’s Eero Signal Introduces Cellular Backup for Home Internet Outages

    February 15, 2026

    AI Safety Researcher Resigns, Warns ‘World Is in Peril’ Amid Broader Industry Concerns

    February 15, 2026

    OpenAI Disbands Mission Alignment Team Amid Internal Restructuring And Safety Concerns

    February 14, 2026

    Startup’s New Chip Tech Aims to Make Luxury Goods Harder to Fake

    February 14, 2026
    Top Reviews
    Tallwire
    Facebook X (Twitter) LinkedIn Threads Instagram RSS
    • Tech
    • Entertainment
    • Business
    • Government
    • Academia
    • Transportation
    • Legal
    • Press Kit
    © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

    Type above and press Enter to search. Press Esc to cancel.