Chrome Extensions Steal 900,000 ChatGPT and DeepSeek Chats

Related

Hackers Target Android Users With Fake ChatGPT Apps to Deliver Malware

What happened Cybercriminals are targeting Android users with fake ChatGPT...

Acting CISA Director Uploaded Sensitive Contracting Documents to Public ChatGPT

What happened The acting CISA director uploaded sensitive contracting documents...

OpenAI Denies Claims of Ads Rolling Out on ChatGPT Paid Plans

What happened Reports circulated that OpenAI planned to introduce ads...

Share

What happened

Two Chrome extensions were caught stealing ChatGPT and DeepSeek chats from over 900,000 users. Researchers at PrismSec discovered that extensions “ChatEnhancer” and “DeepSeek Plus” exfiltrated conversation data to attacker-controlled servers. The malicious code harvested prompts, responses, and metadata from browser sessions, sending the information via HTTPS POST requests. Both extensions were downloaded through the Chrome Web Store and appeared legitimate. Exploitation exposed AI interaction logs, which could reveal sensitive business, personal, or research information.

Who is affected

End users of the Chrome extensions, including AI practitioners, businesses, and individuals, faced direct data exfiltration and potential secondary compromise.

Why CISOs should care

Browser extension compromise risks data leakage, intellectual property theft, and privacy violations, especially for enterprises using AI tools in workflows.

3 practical actions

Remove malicious extensions: Audit and uninstall risky browser extensions immediately.

Monitor sensitive AI interactions: Track unusual access or export of ChatGPT or DeepSeek data.

Educate employees: Raise awareness about extension risks and secure installation practices.

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.