browser extensions

browser-extensions-with-8-million-users-collect-extended-ai-conversations

Browser extensions with 8 million users collect extended AI conversations

Besides ChatGPT, Claude, and Gemini, the extensions harvest all conversations from Copilot, Perplexity, DeepSeek, Grok, and Meta AI. Koi said the full description of the data captured includes:

  • Every prompt a user sends to the AI
  • Every response received
  • Conversation identifiers and timestamps
  • Session metadata
  • The specific AI platform and model used

The executor script runs independently from the VPN networking, ad blocking, or other core functionality. That means that even when a user toggles off VPN networking, AI protection, ad blocking, or other functions, the conversation collection continues. The only way to stop the harvesting is to disable the extension in the browser settings or to uninstall it.

Koi said it first discovered the conversation harvesting in Urban VPN Proxy, a VPN routing extension that lists “AI protection” as one of its benefits. The data collection began in early July with the release of version 5.5.0.

“Anyone who used ChatGPT, Claude, Gemini, or the other targeted platforms while Urban VPN was installed after July 9, 2025 should assume those conversations are now on Urban VPN’s servers and have been shared with third parties,” the company said. “Medical questions, financial details, proprietary code, personal dilemmas—all of it, sold for ‘marketing analytics purposes.’”

Following that discovery, the security firm uncovered seven additional extensions with identical AI harvesting functionality. Four of the extensions are available in the Chrome Web Store. The other four are on the Edge add-ons page. Collectively, they have been installed more than 8 million times.

They are:

Chrome Store

  • Urban VPN Proxy: 6 million users
  • 1ClickVPN Proxy: 600,000 users
  • Urban Browser Guard: 40,000 users
  • Urban Ad Blocker: 10,000 users

Edge Add-ons:

  • Urban VPN Proxy: 1,32 million users
  • 1ClickVPN Proxy: 36,459 users
  • Urban Browser Guard – 12,624 users
  • Urban Ad Blocker – 6,476 users

Read the fine print

The extensions come with conflicting messages about how they handle bot conversations, which often contain deeply personal information about users’ physical and mental health, finances, personal relationships, and other sensitive information that could be a gold mine for marketers and data brokers. The Urban VPN Proxy in the Chrome Web Store, for instance, lists “AI protection” as a benefit. It goes on to say:

Browser extensions with 8 million users collect extended AI conversations Read More »

chrome’s-manifest-v3,-and-its-changes-for-ad-blocking,-are-coming-real-soon

Chrome’s Manifest V3, and its changes for ad blocking, are coming real soon

Chrome Manifest V3 —

Chrome is warning users that their extension makers need to update soon.

Chrome logo, squared off in the style of a popular ad-blocking logo

Ron Amadeo

Google Chrome’s long, long project to implement a new browser extension platform is seemingly going to happen, for real, after six years of cautious movement.

One of the first ways people are seeing this is if they use uBlock Origin, a popular ad-blocking extension, as noted by Bleeping Computer. Recently, Chrome users have seen warnings pop up that “This extension may soon no longer be supported,” with links asking the user to “Remove or replace it with similar extensions” from Chrome’s Web Store. You might see a similar warning on some extensions if you head to Chrome’s Extensions page (chrome://extensions).

What’s happening is Chrome preparing to make Manifest V3 required for extensions that want to run on its platform. First announced in 2018, the last word on Manifest V3 was that V2 extensions would start being nudged out in early June on the Beta, Dev, and Canary update channels. Users will be able to manually re-enable V2 extensions “for a short time,” Google has said, “but over time, this toggle will go away as well.” The shift for enterprise Chrome deployments is expected to be put off until June 2025.

Google has said that its new extension platform was built for “improving the security, privacy, performance, and trustworthiness of the extension ecosystem.” The Electronic Frontier Foundation (EFF) disagrees most strongly with the security aspect, and Firefox-maker Mozilla, while intending to support V3 extensions for cross-browser compatibility, has no plans to cut off support for V2 extensions, signaling that it doesn’t see the big improvement.

Perhaps the biggest point of friction is with ad blockers. Google has said it “isn’t killing ad blockers” but “making them safer,” in an explanatory blog post. Google noted in November 2023 that Manifest V3 allowed for a greater number, and more dynamic updating, of content-blocking rules in extensions, specifically ad blockers.

But one of the biggest changes is in disallowing “remotely hosted code,” which includes the filtering lists that ad blockers keep regularly updated. Ad blockers that want to update their filtering lists, perhaps in response to pivots by platforms like Google’s YouTube and ad servers, will have to do so through the Chrome Web Store’s review process. Ad-blocking coders see it as an intentional gatekeeping and slowing.

Google said before the initial May push toward V3 that 85 percent of actively maintained extensions in its store had Manifest V3 versions ready. Raymond Hill wrote on uBlock Origin’s GitHub page Friday that there will not be a full version of uBlock Origin that works with Manifest V3, but instead a “Lite” version that is “a pared-down version of uBO with a best effort at converting filter lists used by uBO into a Manifest V3-compliant approach.”

Chrome’s Manifest V3, and its changes for ad blocking, are coming real soon Read More »