Urban VPN Proxy Surreptitiously Intercepts AI Chats

Published: (December 24, 2025 at 07:03 AM EST)
2 min read

Source: Schneier on Security

Overview

A new threat has emerged: the Urban VPN Proxy extension is capable of silently intercepting conversations on a wide range of AI chat services. The extension installs a dedicated “executor” script for each platform, allowing it to capture user inputs and AI responses without the user’s knowledge.

Targeted AI Platforms

  • ChatGPT
  • Claude
  • Gemini
  • Microsoft Copilot
  • Perplexity
  • DeepSeek
  • Grok (xAI)
  • Meta AI

How It Works

For each of the platforms listed above, the extension includes a platform‑specific executor script. These scripts:

  1. Hook into the web page’s JavaScript environment.
  2. Listen for outgoing API calls that contain the user’s prompt.
  3. Capture the AI’s response before it is rendered on the screen.
  4. Store the intercepted data locally or forward it to a remote server controlled by the attacker.

The approach is “surreptitious” because it operates entirely within the browser extension’s sandbox, making detection difficult for the average user.

Potential Risks

  • Privacy breach: Sensitive or confidential information shared with AI assistants could be exfiltrated.
  • Intellectual property theft: Proprietary prompts or generated content may be harvested.
  • Credential leakage: If users paste passwords or API keys into a chat, those could be captured.

Mitigation Strategies

  • Audit extensions: Regularly review installed browser extensions and remove any that are unnecessary or untrusted.
  • Use isolated browsers: Run AI chat sessions in a dedicated, minimal‑extension browser profile.
  • Network monitoring: Employ tools that alert on unexpected outbound traffic from your browser.
  • Stay informed: Follow security advisories from reputable sources (e.g., Schneier on Security) for updates on emerging threats.

The information above reflects the findings reported by Schneier on Security on December 24 2025.

Back to Blog

Related posts

Read more »

Friday Squid Blogging: Petting a Squid

Video from Reddit shows what could go wrong when you try to pet a—looks like a Humboldt—squid. As usual, you can also use this squid post to talk about the secu...

AI Advertising Company Hacked

At least some of this is coming to light: Doublespeed, a startup backed by Andreessen Horowitz a16z that uses a phone farm to manage at least hundreds of AI-gen...

Chinese Surveillance and AI

New report: “The Party’s AI: How China’s New AI Systems are Reshaping Human Rights.” From a summary article: China is already the world’s largest exporter of AI...