Breaking
Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech • Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis
SECURITY

Analysis: Featured Chrome Browser Extension Caught Intercepting Millions of Users' AI Chats

Urban VPN Proxy: A Privacy Conundrum for AI Chat Users

Urban VPN Proxy: A Privacy Conundrum for AI Chat Users

In the rapidly evolving world of artificial intelligence (AI), privacy concerns are escalating. A recent discovery has shed light on a Google Chrome extension named Urban VPN Proxy, which has been covertly gathering data from millions of users engaging with various AI-powered chatbots.

The Extension in Question

Urban VPN Proxy, with a 4.7 rating on the Google Chrome Web Store, claims to provide secure VPN access and protect users' online identities. However, an update released on July 9, 2025, enabled the extension to intercept and collect AI chat data without user consent.

Data Collection and Transmission

The extension collects prompts entered by users, chatbot responses, conversation identifiers, timestamps, session metadata, and the AI platform and model used. The data is exfiltrated to two remote servers, "analytics.urban-vpn[.]com" and "stats.urban-vpn[.]com"]."

Secondary Uses of Collected Data

Urban VPN's updated privacy policy states that the collected AI prompts are used for enhancing Safe Browsing and marketing analytics purposes. However, any secondary use of the data is carried out on de-identified and anonymized data.

Third-Party Sharing and Alleged Misuse of Data

One of the third-parties Urban VPN shares "Web Browsing Data" with is an affiliated ad intelligence and brand monitoring firm named BIScience. The company uses the raw data to create insights that are commercially used and shared with Business Partners.

Implications for North East India and Beyond

As AI-powered chatbots gain traction in India, including the North East region, incidents like this underscore the need for heightened awareness about data privacy. Users must exercise caution when using extensions and be vigilant about the data they share online.

Reflections and Future Steps

The removal of the four extensions from the Chrome Web Store and Microsoft's Edge add-ons marketplace is a step in the right direction. However, it is crucial for extension marketplaces to maintain transparency, enforce stricter policies, and provide clearer disclosures to users.