Security company Koi finds browser extensions with 8M+ total installs that collected users' conversations with AI chatbots and sold them for marketing use
Browser extensions with more than 8 million installs are harvesting users' complete and extended AI conversations and selling …
Ars TechnicaDan Goodin
Context & Ripple Effects
This extends a recurring browser-extension privacy pattern: a 2019 case involved extensions leaking sensitive data to a marketing-intelligence service, while a 2025 investigation found extensions overriding browser protections for paid web scraping.
The distinction is the data layer. As AI chat interfaces become places where users disclose work and personal context, extensions can capture more revealing material than conventional browsing histories; separate research on AI romance chatbots similarly found extensive collection and possible sharing of intimate data.
First-order effects
People using the identified extensions may have complete or extended AI-chat conversations routed into marketing use, exposing prompts that may contain sensitive personal or work context.
The extension operators implicated by Koi's findings face heightened scrutiny over their data collection and sale practices, while Koi gains a concrete demonstration of the browser-extension risk it tracks.
Second-order effects
Browser makers, extension-store operators, and enterprise security teams are likely to review whether installed add-ons can read AI-chat pages and whether their permissions match their stated purpose—an issue sharpened by extensions that overrode browser protections for paid scraping.
Marketing-data buyers face a weaker assurance that conversational data was obtained with meaningful user understanding, increasing the value of provenance checks over simply acquiring more behavioral data.
Third-order effects
If AI conversations remain accessible through broadly permissioned browser add-ons, extension vetting will increasingly need to treat chatbot transcripts as a distinct sensitive-data category, not merely another browsing signal.
The pattern points toward a trust divide between AI services and the browser layer around them: earlier extension data leakage to a marketing service and this case suggest that third-party tooling can become the less controlled path to AI-user data.
The trend: AI chat is becoming a high-value but poorly bounded data surface, pushing browser-extension permissions and data provenance toward greater security and privacy scrutiny.
Among the other lessons learned here, there's one the article doesn't point out: the infrastructure for VPNs is expensive to run. If someone is offering a free VPN, there's going to be a catch; and if you can't see what it is, then you're signing a deal with the devil arstechnic…
Cyberattack on AI infrastructure and users. Chrome extensions with over 8 million users intercepted, hijacked and resold conversations with AI chatbots like ChatGPT, Claude, Gemini. Bogus “VPN” extension. Affected: every prompt sent to the AI, responses www.koi.ai/blog/urban-v…
Oh, I'm sure that LLM tracking data is top-notch.... Right... -> Browser extensions with 8 million users collect extended AI conversations. The extensions harvest full AI conversations over months. — As @lilyray.nyc said on X, “So that's where (some of) the LLM tracking compan…
Chrome and Edge extensions auto-update by default. Users who installed Urban VPN for its stated purpose - VPN functionality - woke up one day with new code silently harvesting their AI conversations. — www.koi.ai/blog/urban-v...
These browser extensions that advertised VPN and ad-blocking functions were spying on user chatbot conversations and selling them to marketers. arstechnica.com/security/202... [image]
Browser extensions with 8 million users collect extended AI conversations — https://arstechnica.com/... The extensions, available for Chromium browsers, harvest full AI conversations over months
Urban VPN, Urban Ad Blocker, 1Click VPN, and 1Click Ad Blocker browser plugins found collecting prompts sent to ChatGPT and other AIs. https://arstechnica.com/...