Investigations found that several popular Chrome and Edge extensions collected sensitive user data at scale, including AI chat conversations and browsing activity, often with limited transparency. Reports said extensions such as Urban VPN, Stylish, Poper Blocker, SimilarWeb, StayFocusd, CrxMouse, WhatRuns, and StayFree had either directly exfiltrated AI chat content or retained the remote-configurable capability to do so, affecting more than 7 million installs combined; a separate report alleged Urban VPN-related "privacy" extensions monetized data from roughly 8 million users. Researchers also reported that Urban VPN had previously scraped AI conversations and that its user-facing opt-out of data collection control was inverted in code, potentially leaving collection enabled even when users believed they had disabled it.
Urban VPN was also found to contain a high-severity browser-extension flaw that let any website send privileged postMessage commands without origin validation, allowing attackers to disconnect the VPN, reroute traffic, change bypass settings, disable privacy protections, disable competing extensions, and query extension state. The issue was reportedly fixed in Urban VPN version 5.12.5 by limiting accepted messages to a read-only query, while broader concerns about data collection practices remained. Together, the findings raised concerns that widely installed browser extensions marketed around convenience or privacy could both harvest sensitive content and expose users to direct manipulation of browser security controls.

Trace attribution and downstream blast radius.
15 events from the most recent confirmed update back to the earliest known activity.
Signer.Digital released extension version 5.2.0 and native host version 6.0.0.0 to fix the drive-by RCE vulnerability. The native host update was the effective remediation, while the extension patch alone did not fully mitigate the issue.
Urban VPN told the researchers that the update had been completed on 23 March 2026. This statement conflicted with the later-noted Chrome Web Store publication date for version 5.12.5.
Signer.Digital later confirmed it could reproduce the reported remote code execution vulnerability. This validated the researchers' findings during coordinated disclosure.
Urban VPN published version 5.12.5 to the Chrome Web Store, restricting the vulnerable message interface to a single read-only query and blocking the prior control commands. The patch addressed the postMessage command-injection issue.
Researchers reported the Signer.Digital issue to CERT-In because of the extension's use in banking and healthcare contexts. The escalation reflected concern over the product's broad deployment in India.
Signer.Digital acknowledged receipt of the researchers' vulnerability report. This was the vendor's first documented response in the coordinated disclosure timeline.
Researchers reported a drive-by remote code execution vulnerability in Signer.Digital's browser extension and native host to the vendor, including a proof of concept and video demonstration. The issue allowed arbitrary websites to trigger code execution on affected Windows systems.
WhatRuns stopped collecting AI chats in version 1.10.0. The change was identified in later research on browser extensions scraping AI chats and URLs.
Urban VPN told the researchers that fixes for the reported postMessage vulnerability would be released soon. This marked a vendor status update during the disclosure process.
Researchers formally reported the Urban VPN postMessage command-injection vulnerability with a proof of concept. Urban VPN acknowledged the report the same day.
Researchers began initial outreach to Urban VPN regarding the extension's postMessage issue. The flaw allowed any website to send privileged commands to the extension without origin verification.
Koi Security reported that Urban VPN appeared to capture user conversations with ChatGPT, Gemini, and Claude. Later reporting cited this as prior December 2025 exposure of Urban VPN's AI-chat scraping behavior.
Public reporting said Signer.Digital's auto-update mechanism appeared broken because the update feed advertised version 3.3.0.0, preventing existing 5.x native hosts from automatically updating to the fixed 6.0.0.0 release. As a result, manual reinstallation of the host was required for many users.
Researchers reported that several popular Chrome extensions with more than 7 million combined installs scraped AI chats, browsing URLs, or both, with some behavior controlled remotely after installation. The report named Stylish, Poper Blocker, SimilarWeb, StayFocusd, CrxMouse, WhatRuns, StayFree, and noted UrbanVPN had historically scraped AI chats but no longer did so at the time of testing.
Public reporting described how any website could control Urban VPN through postMessage using the public extension ID and hardcoded sender string "Toad," enabling actions such as disconnecting the VPN, rerouting traffic, changing bypass settings, and disabling protections. The report also said the extension's data-collection opt-out logic was inverted and broader data-collection behavior remained unchanged after the patch.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
amibeingpwned.com
Open sourceamibeingpwned.com
Open sourceamibeingpwned.com
Open sourcekoi.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.