Technology
CSO Online
WebProNews
The Hacker News
3 outlets
Tuesday, December 16, 2025

Urban VPN caught logging private ChatGPT and Claude chats

Source: CSO Online
Read original|GOOGL $302.02

TL;DR

AI-Summarizedfrom 3 sources

Security researchers have discovered that Urban VPN, a Chrome extension with millions of installs and even a "Featured" badge from Google, has been quietly intercepting users’ conversations with AI chatbots like ChatGPT, Claude and Gemini. Analysis by cybersecurity firm Koi shows the extension injecting JavaScript into AI sites to capture prompts, responses and metadata, then sending that data to remote servers regardless of whether the VPN is actually in use. A separate, more detailed write‑up notes that Urban VPN’s business model appears to revolve around monetizing this data, effectively turning highly sensitive AI queries into an analytics product sold to third parties. The case highlights just how fragile privacy can be around generative‑AI tools, where people routinely paste medical, financial and work information into chats they assume are confidential. It also raises hard questions for platform operators like Google, whose endorsement signals clearly weren’t enough to protect users from a rogue extension.

About this summary

This article aggregates reporting from 3 news sources. The TL;DR is AI-generated from original reporting. Race to AGI's analysis provides editorial context on implications for AGI development.

3 sources covering this story|3 companies mentioned

Companies Mentioned

OpenAI
OpenAI
AI Lab|United States
Valuation: $500.0B
Anthropic
Anthropic
AI Lab|United States
Valuation: $183.0B
Google
Google
Cloud|United States
Valuation: $3930.0B
GOOGLNASDAQ$302.02

Coverage Sources

CSO Online
WebProNews
The Hacker News
CSO Online
CSO Online
Read
WebProNews
WebProNews
Read
The Hacker News
The Hacker News
Read