📰 AI News: Featured Chrome VPN Caught Intercepting Millions Of AI Chats
📝 TL;DR A massively popular Chrome VPN extension with a “Featured” badge was quietly logging people’s AI chats and sending them to its own servers. If you are using a browser VPN or “AI protection” extension, this is your reminder to check what you have installed. 🧠 Overview A Chrome extension with around six million users and an official “Featured” badge was found intercepting every prompt and response from major AI chatbots, including ChatGPT, Claude, Copilot, Gemini, DeepSeek, Grok, Meta AI, and Perplexity. The data was captured in the browser and forwarded to servers controlled by the extension’s publisher and an associated data company. This is less about a single bad extension and more about how easily trust in the browser extension ecosystem can be abused. 📜 The Announcement On December 15, 2025, security researchers revealed that a popular VPN browser extension turned into an AI data vacuum after a July 9 update. The extension, promoted as a “secure free VPN” and carrying a “Featured” badge in the Chrome Web Store, added code to silently monitor AI chat pages and harvest conversations by default. The same AI chat harvesting behavior was also spotted in three related extensions across Chrome and Edge, pushing the total affected install base to over eight million users. ⚙️ How It Works • Targeted AI sites - The extension ships special scripts for each major AI chatbot, for example for ChatGPT, Claude, Gemini and others, which activate whenever you visit those sites. • Browser API hijack - The script overrides key browser network functions like fetch and XMLHttpRequest so every AI request goes through the extension first. • Full conversation capture - It collects your prompts, the AI responses, conversation IDs, timestamps, session metadata, and which AI platform or model you are using. • Silent data exfiltration - That data is then sent to remote analytics servers controlled by the extension operator and shared with an affiliated ad intelligence and brand monitoring company.