Chrome Extensions Steal 900,000 ChatGPT and DeepSeek Chats

Related

Pentagon CIO Kirsten Davies Announces New Team Appointments

What happened Pentagon Chief Information Officer Kirsten Davies announced several...

Carnival Corporation Probes Data Breach After Claims of 8.7 Million Records Theft

What happened Carnival Corporation is investigating a potential data breach...

Grinex Exchange Blames Western Intelligence for $13.7M Crypto Hack

What happened Kyrgyzstan-based cryptocurrency exchange Grinex suspended operations on April...

Payouts King Ransomware Uses QEMU VMs to Bypass Endpoint Security

What happened Sophos researchers have documented two active campaigns in...

Share

What happened

Two Chrome extensions were caught stealing ChatGPT and DeepSeek chats from over 900,000 users. Researchers at PrismSec discovered that extensions “ChatEnhancer” and “DeepSeek Plus” exfiltrated conversation data to attacker-controlled servers. The malicious code harvested prompts, responses, and metadata from browser sessions, sending the information via HTTPS POST requests. Both extensions were downloaded through the Chrome Web Store and appeared legitimate. Exploitation exposed AI interaction logs, which could reveal sensitive business, personal, or research information.

Who is affected

End users of the Chrome extensions, including AI practitioners, businesses, and individuals, faced direct data exfiltration and potential secondary compromise.

Why CISOs should care

Browser extension compromise risks data leakage, intellectual property theft, and privacy violations, especially for enterprises using AI tools in workflows.

3 practical actions

Remove malicious extensions: Audit and uninstall risky browser extensions immediately.

Monitor sensitive AI interactions: Track unusual access or export of ChatGPT or DeepSeek data.

Educate employees: Raise awareness about extension risks and secure installation practices.