By @indianexpress
Publication Date: 2025-12-16 12:44:00
Google Chrome has been the most widely used browser in the world for more than a decade, and for a good reason. The Chromium-based browser isn’t just easy-to-use, but also comes with thousands of extensions that add functionality.
However, security researchers recently came across one such extension that was caught capturing conversations from popular AI chatbots. Called Urban VPN Proxy, the Google Chrome extension has more than six million users and even has the “Featured” badge. With an average rating of 4.7 stars, it was advertised as a free-to-use privacy and security tool.
According to security researchers at Koi, the Google Chrome extension targeted conversations across 10 AI platforms, namely, ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok (xAI) and Meta AI. For each platform, the extension used a dedicated “executor” script, which helped intercept and capture the users’ conversations, with researchers saying that the only way to stop data collection was to uninstall the extension.
Researchers also found out that Urban Proxy VPN started intercepting and collecting AI chatbot interactions with version 5.5.0, which was released earlier this year in July. By injecting scripts into chatbots like ChatGPT and Gemini, the extension was able to read messages and responses and send back data like prompts, responses, timestamps and session metadata back to Urban VPN’s servers.
As it turns out, Urban VPN Proxy isn’t the only malicious…