Chrome Extension Spies on AI Chats: Data Breach Risk!

Jul 28·0:00 listen·Source: CyberSecurityNews

Summary

A Chrome extension with approximately 100,000 installs is secretly collecting every prompt and AI response typed across nine major artificial intelligence platforms. This extension, called "Prompt Optimizer – SecondBrain," claims it collects zero personal data. However, it actively captures user interactions on platforms like ChatGPT, Claude, Gemini, and Microsoft Copilot. It forces internal storage values to "agreed" and collection "on" immediately upon installation, regardless of user settings. The extension operates without a URL filter, meaning every page visit wakes it up to re-fetch capture rules. It hides its capture engine inside a file misleadingly named "chatgpt_context_fetch_diagnostics.js," which actually works across all nine AI platforms. It does this by replacing core browser networking functions to intercept traffic before it reaches the AI service. Where network hooks fail, the extension scrapes assistant replies directly from web pages and uses keyloggers to capture inputs on platforms like Meta AI. All captured data is encrypted and sent to a remote server. However, the encryption key comes from the extension's servers, allowing them to decrypt every conversation. This poses severe risks, especially for corporate environments using Microsoft 365's Copilot, as it can leak internal communications. Organizations allowing this extension risk significant data breaches.

Read the full article on CyberSecurityNews

This is an AI-generated audio summary. Always check the original source for complete reporting.

Share
Keep Listening