logo

You know that generative AI browser assistant extension is probably beaming everything to the cloud, right?

ID: 40e48d55-b146-5568-b177-707885894195

STIX ID: report--40e48d55-b146-5568-b177-707885894195

Feed Name: The Register (Security)

Date Published: 2025-03-25

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Researchers from multiple universities audited 10 generative AI Chrome extensions and found widespread collection and sharing of sensitive data—including full HTML DOMs, form inputs (e.g., SSNs), and user prompts—with both first-party servers and third-party trackers, potentially running afoul of regulations like HIPAA and FERPA. Extensions such as Harpa, MaxAI, and Merlin were flagged as among the most invasive, while Perplexity was comparatively more privacy-friendly; practices observed included storing context across navigation, collecting full page content, and sharing referrers with trackers. The study calls for stricter Chrome Web Store vetting and embedding privacy-by-design, noting most assistants rely on server-side processing and can operate without explicit user interaction.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.