VPN Extension Stole ChatGPT, Gemini Chats From 6M Users

VPN extension stole ChatGPT Gemini chats from 6M users

Researchers say a “Featured” browser VPN extension captured AI prompts and responses across ChatGPT and Gemini, raising new questions about extension reviews and data collection.​

A security report is warning that a popular browser VPN extension “stole” ChatGPT and Gemini chats—by intercepting and exfiltrating prompts and responses—impacting more than 6 million Chrome users tied to Urban VPN Proxy. Researchers at Koi Security say the AI chat harvesting was enabled by default in an update and could continue regardless of whether the VPN was turned on.​

What happened

Koi Security says Urban VPN Proxy, a Chrome extension with over 6 million users, included code that intercepts conversations with major AI platforms, including ChatGPT and Google Gemini. The Hacker News reported the extension had a “Featured” badge on the Chrome Web Store and a large install base on Microsoft Edge as well.​

According to Koi, the harvesting capability was introduced in Urban VPN Proxy version 5.5.0, released on July 9, 2025, and rolled out via standard browser extension auto-updates. Infosecurity Magazine summarized Koi’s findings as capturing AI chat traffic and sending it to company-controlled servers even when the VPN feature was not enabled.​

Timeline (reported)

Date / Period Reported development Why it matters
Before v5.5.0 Koi says earlier versions did not include AI conversation harvesting. ​ Suggests the AI chat capture behavior was added later via update. ​
July 9, 2025 Koi and The Hacker News cite release of v5.5.0 with AI harvesting enabled by default. ​ Users could be opted in silently through auto-updates. ​
July 2025–Dec 2025 Koi says conversations with targeted AI platforms were captured and exfiltrated during this period. ​ Expands risk window for exposed prompts, responses, and metadata. ​

How the extension accessed chats

Koi says Urban VPN Proxy injected “executor” scripts into AI chat sites, including dedicated files such as chatgpt.js and gemini.js. The report says those scripts then overrode browser networking functions like fetch() and XMLHttpRequest to intercept requests and responses before they were rendered.​

The Hacker News and Koi both say the captured data was then exfiltrated to endpoints including analytics.urban-vpn.com and stats.urban-vpn.com. Koi further states there was no user-facing toggle to disable this harvesting, and the only reliable way to stop collection was uninstalling the extension.​

Reported data collected

Koi and The Hacker News say the extension captured user prompts, chatbot responses, conversation identifiers, timestamps, session metadata, and AI platform/model information. Infosecurity Magazine similarly described collection of prompts, responses, timestamps, and session identifiers as part of the alleged harvesting.​

Koi warns that because prompts often include highly sensitive content—such as medical questions, financial discussions, or workplace information—users should assume any AI chats made after the July 9, 2025 update may have been captured if the extension was installed.​

Scale and other extensions

Koi says the same AI harvesting capability appeared not only in Urban VPN Proxy, but also in other related extensions across Chrome and Microsoft Edge, bringing the total affected user base to over 8 million across marketplaces. The Hacker News reported the same family of extensions and said several carried “Featured” badges, increasing perceived trust.​

Reported affected extensions and users

Extension (store) Reported users Notes from Koi’s report
Urban VPN Proxy (Chrome) 6,000,000 AI harvesting described as enabled by default after v5.5.0. ​
1ClickVPN Proxy (Chrome) 600,000 Reported to share identical harvesting backend. ​
Urban Browser Guard (Chrome) 40,000 Reported to include same harvesting logic. ​
Urban Ad Blocker (Chrome) 10,000 Reported to include same harvesting logic. ​
Urban VPN Proxy (Edge) 1,323,622 Reported installs on Microsoft Edge Add-ons. ​
1ClickVPN Proxy (Edge) 36,459 Reported installs on Microsoft Edge Add-ons. ​
Urban Browser Guard (Edge) 12,624 Reported installs on Microsoft Edge Add-ons. ​
Urban Ad Blocker (Edge) 6,476 Reported installs on Microsoft Edge Add-ons. ​

Why this raised alarms (badges, disclosure, and data brokers)

One reason the report drew attention is that Urban VPN Proxy carried a “Featured badge,” which Google says is assigned to extensions that “meet a high standard of user experience and design,” and are manually evaluated by Chrome team members. Koi argues this kind of store badge can function like an implicit endorsement, making users more likely to install an extension without deeper scrutiny.​

Koi also links the ecosystem to data monetization, stating Urban VPN is affiliated with BiScience (B.I Science), described in the report as a data broker with prior documentation by independent researchers. The Hacker News similarly reported that Urban VPN’s policy referenced sharing browsing data with an affiliated firm named BIScience and discussed prior public research alleging clickstream collection practices.​

What users and organizations can do next

Koi’s guidance is straightforward: if any of the listed extensions are installed, uninstalling is the only sure way to stop the reported AI chat harvesting. Koi also advises users to assume any ChatGPT, Gemini, or other supported AI chats made since July 9, 2025 could have been captured if Urban VPN Proxy was installed.​

For organizations, the incident highlights why browser extensions should be treated like high-privilege software, because Koi’s technical description shows how extensions can inject scripts and intercept web traffic inside sensitive sites. Where possible, security teams can reduce exposure by limiting extension installation to approved allowlists and reviewing extensions that request broad access to “site data” or web activity.​

What comes next

As of the published reports, The Hacker News said it contacted Google and Microsoft for comment, and Infosecurity Magazine reported Urban VPN was contacted as well, with no response at the time of writing.​


Subscribe to Our Newsletter

Related Articles

Top Trending

Goku AI Text-to-Video
Goku AI: The New Text-to-Video Competitor Challenging Sora
US-China Relations 2026
US-China Relations 2026: The "Great Power" Competition Report
AI Market Correction 2026
The "AI Bubble" vs. Real Utility: A 2026 Market Correction?
NVIDIA Cosmos
NVIDIA’s "Cosmos" AI Model & The Vera Rubin Superchip
Styx Blades of Greed
The Goblin Goes Open World: How Styx: Blades of Greed is Reinventing the AA Stealth Genre.

LIFESTYLE

Benefits of Living in an Eco-Friendly Community featured image
Go Green Together: 12 Benefits of Living in an Eco-Friendly Community!
Happy new year 2026 global celebration
Happy New Year 2026: Celebrate Around the World With Global Traditions
dubai beach day itinerary
From Sunrise Yoga to Sunset Cocktails: The Perfect Beach Day Itinerary – Your Step-by-Step Guide to a Day by the Water
Ford F-150 Vs Ram 1500 Vs Chevy Silverado
The "Big 3" Battle: 10 Key Differences Between the Ford F-150, Ram 1500, and Chevy Silverado
Zytescintizivad Spread Taking Over Modern Kitchens
Zytescintizivad Spread: A New Superfood Taking Over Modern Kitchens

Entertainment

Samsung’s 130-Inch Micro RGB TV The Wall Comes Home
Samsung’s 130-Inch Micro RGB TV: The "Wall" Comes Home
MrBeast Copyright Gambit
Beyond The Paywall: The MrBeast Copyright Gambit And The New Rules Of Co-Streaming Ownership
Stranger Things Finale Crashes Netflix
Stranger Things Finale Draws 137M Views, Crashes Netflix
Demon Slayer Infinity Castle Part 2 release date
Demon Slayer Infinity Castle Part 2 Release Date: Crunchyroll Denies Sequel Timing Rumors
BTS New Album 20 March 2026
BTS to Release New Album March 20, 2026

GAMING

Styx Blades of Greed
The Goblin Goes Open World: How Styx: Blades of Greed is Reinventing the AA Stealth Genre.
Resident Evil Requiem Switch 2
Resident Evil Requiem: First Look at "Open City" Gameplay on Switch 2
High-performance gaming setup with clear monitor display and low-latency peripherals. n Improve Your Gaming Performance Instantly
Improve Your Gaming Performance Instantly: 10 Fast Fixes That Actually Work
Learning Games for Toddlers
Learning Games For Toddlers: Top 10 Ad-Free Educational Games For 2026
Gamification In Education
Screen Time That Counts: Why Gamification Is the Future of Learning

BUSINESS

IMF 2026 Outlook Stable But Fragile
Global Economic Outlook: IMF Predicts 3.1% Growth but "Downside Risks" Remain
India Rice Exports
India’s Rice Dominance: How Strategic Export Shifts are Reshaping South Asian Trade in 2026
Mistakes to Avoid When Seeking Small Business Funding featured image
15 Mistakes to Avoid As New Entrepreneurs When Seeking Small Business Funding
Global stock markets break record highs featured image
Global Stock Markets Surge to Record Highs Across Continents: What’s Powering the Rally—and What Could Break It
Embodied Intelligence
Beyond Screen-Bound AI: How Embodied Intelligence is Reshaping Industrial Logistics in 2026

TECHNOLOGY

Goku AI Text-to-Video
Goku AI: The New Text-to-Video Competitor Challenging Sora
AI Market Correction 2026
The "AI Bubble" vs. Real Utility: A 2026 Market Correction?
NVIDIA Cosmos
NVIDIA’s "Cosmos" AI Model & The Vera Rubin Superchip
Styx Blades of Greed
The Goblin Goes Open World: How Styx: Blades of Greed is Reinventing the AA Stealth Genre.
Samsung’s 130-Inch Micro RGB TV The Wall Comes Home
Samsung’s 130-Inch Micro RGB TV: The "Wall" Comes Home

HEALTH

Bio Wearables For Stress
Post-Holiday Wellness: The Rise of "Bio-Wearables" for Stress
ChatGPT Health Medical Records
Beyond the Chatbot: Why OpenAI’s Entry into Medical Records is the Ultimate Test of Public Trust in the AI Era
A health worker registers an elderly patient using a laptop at a rural health clinic in Africa
Digital Health Sovereignty: The 2026 Push for National Digital Health Records in Rural Economies
Digital Detox for Kids
Digital Detox for Kids: Balancing Online Play With Outdoor Fun [2026 Guide]
Worlds Heaviest Man Dies
Former World's Heaviest Man Dies at 41: 1,322-Pound Weight Led to Fatal Kidney Infection