Browser Extension Harvests 8M Users' AI Chatbot Data
Overview
Urban VPN Proxy, a browser extension that claims to enhance user privacy, has been found to collect sensitive data from interactions with various AI chatbots, including ChatGPT, Claude, Gemini, and Copilot. This means that conversations users believe are private may actually be harvested and stored by the extension. Researchers discovered that the extension is gathering information without user consent, raising serious privacy concerns. With around 8 million users potentially affected, the implications are significant, as sensitive personal data could be misused. Users should be cautious about the extensions they install and the permissions they grant, especially those that claim to protect their privacy.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Urban VPN Proxy extension, ChatGPT, Claude, Gemini, Copilot
- Action Required: Users should uninstall the Urban VPN Proxy extension and review other extensions for privacy practices.
- Timeline: Newly disclosed
Original Article Summary
Urban VPN Proxy, which claims to protect users' privacy, collects data from conversations with ChatGPT, Claude, Gemini, Copilot and other AI assistants.
Impact
Urban VPN Proxy extension, ChatGPT, Claude, Gemini, Copilot
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should uninstall the Urban VPN Proxy extension and review other extensions for privacy practices.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.