
Besides ChatGPT, Claude, and Gemini, the extensions harvest all conversations from Copilot, Perplexity, DeepSeek, Grok, and Meta AI. Koi said the total description of the info captured includes:
- Every prompt a user sends to the AI
- Every response received
- Conversation identifiers and timestamps
- Session metadata
- The particular AI platform and model used
The executor script runs independently from the VPN networking, ad blocking, or other core functionality. That signifies that even when a user toggles off VPN networking, AI protection, ad blocking, or other functions, the conversation collection continues. The one strategy to stop the harvesting is to disable the extension within the browser settings or to uninstall it.
Koi said it first discovered the conversation harvesting in Urban VPN Proxy, a VPN routing extension that lists “AI protection” as certainly one of its advantages. The information collection began in early July with the discharge of version 5.5.0.
“Anyone who used ChatGPT, Claude, Gemini, or the opposite targeted platforms while Urban VPN was installed after July 9, 2025 should assume those conversations are actually on Urban VPN’s servers and have been shared with third parties,” the corporate said. “Medical questions, financial details, proprietary code, personal dilemmas—all of it, sold for ‘marketing analytics purposes.’”
Following that discovery, the safety firm uncovered seven additional extensions with an identical AI harvesting functionality. 4 of the extensions can be found within the Chrome Web Store. The opposite 4 are on the Edge add-ons page. Collectively, they’ve been installed greater than 8 million times.
They’re:
Chrome Store
- Urban VPN Proxy: 6 million users
- 1ClickVPN Proxy: 600,000 users
- Urban Browser Guard: 40,000 users
- Urban Ad Blocker: 10,000 users
Edge Add-ons:
- Urban VPN Proxy: 1,32 million users
- 1ClickVPN Proxy: 36,459 users
- Urban Browser Guard – 12,624 users
- Urban Ad Blocker – 6,476 users
Read the high-quality print
The extensions include conflicting messages about how they handle bot conversations, which frequently contain deeply personal details about users’ physical and mental health, funds, personal relationships, and other sensitive information that may very well be a gold mine for marketers and data brokers. The Urban VPN Proxy within the Chrome Web Store, as an example, lists “AI protection” as a profit. It goes on to say:
