Technology
CSO Online
WebProNews
The Hacker News
3 outlets
Tuesday, December 16, 2025

Urban VPN caught logging private ChatGPT and Claude chats

Source: CSO OnlineRead original
‘Featured’ Urban VPN caught stealing private AI chats

Summary

Security researchers have discovered that Urban VPN, a Chrome extension with millions of installs and even a "Featured" badge from Google, has been quietly intercepting users’ conversations with AI chatbots like ChatGPT, Claude and Gemini. Analysis by cybersecurity firm Koi shows the extension injecting JavaScript into AI sites to capture prompts, responses and metadata, then sending that data to remote servers regardless of whether the VPN is actually in use. A separate, more detailed write‑up notes that Urban VPN’s business model appears to revolve around monetizing this data, effectively turning highly sensitive AI queries into an analytics product sold to third parties. The case highlights just how fragile privacy can be around generative‑AI tools, where people routinely paste medical, financial and work information into chats they assume are confidential. It also raises hard questions for platform operators like Google, whose endorsement signals clearly weren’t enough to protect users from a rogue extension.

Companies Mentioned

OpenAI
OpenAI
AI Lab|United States
Valuation: $500.0B
Private company - No stock data
Anthropic
Anthropic
AI Lab|United States
Valuation: $183.0B
Private company - No stock data
Google
Google
Cloud|United States
Valuation: $3790.0B
GOOGLNASDAQMarket Closed
At news: $306.57Now: $306.57

Related Deals

Research
Licensing
Partnership
Investment
Drag nodes to explore | Featured companies highlighted
Research

Google and Google DeepMind committed roughly $13.05 million in grants to India’s AI centers of excellence, Wadhwani AI and several Indic‑language AI startups to accelerate AI deployment in health, agriculture, education and smart cities.

GoogleGoogleDeepMindDeepMindIndia AI Centers of Excellence (health, agriculture, education, sustainable cities)Wadhwani AIGnani.AICoRover.AIBharatGen
Dec 2025
Licensing

Disney granted OpenAI’s Sora a one‑year exclusive license to use over 200 Disney, Marvel, Pixar and Star Wars characters for user‑generated AI video content as part of a broader three‑year partnership.

The Walt Disney CompanyOpenAIOpenAIOpenAIOpenAIThe Walt Disney Company
Dec 2025
Partnership

BBVA and OpenAI formed a strategic partnership to co‑develop AI‑powered banking experiences and deploy ChatGPT Enterprise to BBVA’s global workforce.

BBVAOpenAIOpenAI
Dec 2025
Partnership

BBVA and OpenAI entered a strategic partnership to expand ChatGPT Enterprise to BBVA’s global workforce and co-develop AI solutions for banking operations and customer experiences.

BBVAOpenAIOpenAI
Dec 2025
Investment

Disney makes a $1B equity investment in OpenAI alongside a multi-year character-licensing partnership for Sora-generated short videos.

The Walt Disney CompanyOpenAIOpenAI
Dec 2025

Coverage Sources

CSO Online
WebProNews
The Hacker News
CSO Online
CSO Online
Read
WebProNews
WebProNews
Read
The Hacker News
The Hacker News
Read