Skip to main content
  1. Home
  2. Computing
  3. News

Featured Chrome extension could be copying your AI chats

Koi Security says the extension captured AI chat traffic even when its protection features were turned off, despite language about privacy in its listing.

Add as a preferred source on Google
A person using a laptop with a set of code seen on the display.
Sora Shimazaki / Pexels

A security warning is a nasty surprise, especially when the add-on in question claims it exists to protect your privacy. Researchers at Koi Security say Urban VPN Proxy, a VPN extension for Google Chrome and Microsoft Edge, began logging users’ AI assistant conversations and sending them to a data broker.

Urban VPN Proxy looked reputable, with a 4.7-star rating, Google’s featured badge, and more than six million installs on Chrome. Another 1.3 million people installed it on Edge. But Koi says the extension’s behavior changed after a quiet update on July 9, 2025, when the publisher shipped version 5.5.0.

Recommended Videos

From that point, Koi alleges, the extension intercepted both what users typed and what the assistant replied across eight platforms: ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok (xAI), and Meta AI.

The report says the captured prompts and responses were packaged and sent to Urban Cybersecurity’s parent company, BiScience (B.I Science (2009) Ltd), which Koi describes as a data broker that collects browsing history and device IDs at scale. Koi also says it found the same harvesting code in seven other extensions from the same publisher. If you’re still worried about your privacy, check out the best VPN services out now.

The consent line that changes everything

Koi points to Urban VPN Proxy’s setup consent screen, which references processing “ChatAI communication,” plus a privacy policy that describes sharing data for marketing analytics purposes.

Still, the practical reality is harsh. Extensions can auto-update on Chrome and Edge, so people who installed an older version could have been upgraded into chat collection without realizing it. Koi also says the store listing framed the tool as protecting users from entering personal information into AI chatbots, which clashes with the claim that it captured chats whether or not protection features were enabled.

What you should do now

If you used Urban VPN Proxy, assume AI chats since July 9, 2025 may have been exposed. Remove it in Chrome at chrome://extensions or in Edge at edge://extensions, then consider clearing cookies and cached site data. If you shared sensitive details, a password reset is a reasonable precaution.

Google says its featured badge signals best practices and a high standard for user experience and design, but this shows that label isn’t a guarantee. The simplest next step is also the most boring one: audit your extensions, delete anything you don’t trust, and keep the most personal stuff out of chat boxes.

Paulo Vargas
Paulo Vargas is an English major turned reporter turned technical writer, with a career that has always circled back to…
Lenovo’s next ThinkBook looks unbelievably thin in this leak
Say hello to Aeroblade, the ThinkBook that could redefine how thin a laptop can get.
Lenovo ThinkBook Aeroblade front view

Lenovo might have a new obsession, and it's all about being thin. Windows Latest got its hands on marketing images of an unannounced Lenovo laptop, and buried in the files is a name we've never seen before: Aeroblade. The device itself is clearly branded as a ThinkBook, so this could launch as the ThinkBook Aeroblade.

If you're not familiar, ThinkBook sits just below the premium ThinkPad lineup and is built for small and medium businesses who want that ThinkPad look without the ThinkPad price tag.

Read more
Apple fixed three Mac Screen Sharing flaws, and now it’s patching another one
macOS 26.6.1 arrives roughly 10 days after Apple shipped three separate Screen Sharing security fixes in macOS 26.6.
MacBook Pro on Table

Apple has released macOS Tahoe 26.6.1 to fix a Screen Sharing vulnerability that could let an attacker on the same network authenticate without valid credentials.

The timing makes this update more interesting than its small version number suggests. Apple’s security notes for macOS 26.6, released July 27, already listed three separate vulnerabilities affecting Screen Sharing Server.

Read more
Dell’s iconic XPS lineup may be heading into Google’s Googlebook ecosystem
Dell's iconic XPS lineup may be heading to Google's laptop platform for the first time.
Googlebook featured image.

A fresh benchmark leak suggests Dell is quietly building its first Googlebook under the XPS name, joining Lenovo and Asus as the hardware partner for Google's upcoming laptop platform (via Chrome Unboxed).

The leak trail started with an internal board codenamed "Mica" showing up in Chromium's development pipeline. It was tied to Qualcomm's "Bluey" architecture built specifically for Snapdragon X-series Googlebooks. 

Read more