Cybercriminals Deploy Malicious AI Extensions to Steal Private Chat Data
ID: d52cfdaa-6800-5f68-aada-da86b4f20dd3
STIX ID: report--d52cfdaa-6800-5f68-aada-da86b4f20dd3
Feed Name: securityonline.info
## Executive Summary Security researchers found multiple malicious AI browser extensions in official web stores that quietly harvest and exfiltrate complete user conversations and related metadata (conversation IDs, model hostnames, timestamps) by using DOM watchers, injection frameworks, Base64-encoded payloads, and hidden iframes; examples include compromised components in Urban VPN, Smart Sidebar, and Chat AI. The report warns this behavior can expose enterprise secrets at scale and recommends strict extension allow-lists and improved dynamic scanning of extensions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
