Millions May Be Sharing AI Chats Without Knowing It
Security experts have found two popular Chrome browser extensions that secretly read and send users’ ChatGPT and DeepSeek conversations to outside servers without their knowledge. Together, the extensions have been downloaded by more than 900,000 people.
The affected extensions are:
- Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI
- AI Sidebar with Deepseek, ChatGPT, Claude, and more
The extensions claim they only collect basic, anonymous data to improve user experience. In reality, they copy full chat conversations, along with the websites users visit, and send this information to the people who created the extensions.
Experts warn that this stolen information could include personal details, work discussions, or confidential business data. It could be misused for scams, identity theft, or spying on companies.
Researchers say this is part of a growing trend called “Prompt Poaching,” where browser add-ons quietly monitor what people type into AI tools like ChatGPT.
Precautions for Users
Security experts recommend that users:
- Remove suspicious or unused browser extensions immediately
- Avoid installing add-ons from unknown or untrusted developers
- Do not rely on popularity or “Featured” labels as signs of safety
- Avoid sharing sensitive personal or work-related information in AI chats
- Regularly review and limit which extensions have access to your browser
Source: https://thehackernews.com/2026/01/two-chrome-extensions-caught-stealing.html