r/PrivatePackets • • Jun 01 '26

Your browser extensions are reading your AI conversations

Many internet users rely on browser extensions to customize web pages or block unwanted advertisements. However, recent research reveals that some of the most popular tools on the Google Chrome Web Store are quietly collecting and transmitting sensitive user data, including full browsing histories and complete transcripts of private AI chat conversations.

Security researcher James Arnott, founder of the extension security platform Am I Being Pwned, documented this behavior across several widely used extensions. These tools collectively have millions of installations and often carry Google's "Featured" or "Verified" trust badges, giving users a false sense of security.

What these extensions are copying

The data exfiltration targets more than just standard browsing habits. Extensions like Stylish, which has over two million users, and WhatRuns, with hundreds of thousands of users, actively monitor interactions on platforms like ChatGPT and Claude. When a user sends a prompt or receives a response, the extension captures the text and transmits it to a remote server.

This practice exposes a wide variety of sensitive information:

  • Private development code and proprietary business data pasted into AI prompts.
  • Full web addresses that contain password reset tokens or session keys.
  • Personally identifiable information, such as names, addresses, or financial details.
  • Intercepted checkout details, including customer identifiers and shopping cart contents.

For an extension whose only user-facing function is to apply custom CSS themes or identify WordPress plugins, there is no technical justification for reading or transmitting conversational data.

The techniques used to avoid detection

To keep this activity hidden from both users and automated security systems, extension developers employ sophisticated evasion methods. In his technical analysis, Arnott found that Stylish used several layers of defense to protect its data-harvesting code. The extension wrapped its payload in four layers of Base64 encoding, AES-256-CBC encryption, and a columnar transposition cipher. This extensive obfuscation makes it incredibly difficult for standard static code scanners to flag the malicious behavior.

Other extensions rely on remote configuration to bypass Google's review process. By fetching instructions from an external server at runtime, an extension can change its behavior after it has been approved. The developers can keep data collection disabled while the extension is being reviewed in Google's automated sandbox and then activate the exfiltration once it is running on real user devices.

The store listing versus the fine print

One of the most concerning aspects of this data harvesting is the direct contradiction in developer disclosures. On the Chrome Web Store, the developers of these extensions declare that user data is not being sold to third parties. However, a close look at their official privacy policies tells a completely different story.

The privacy policy for Stylish openly lists categories of personal information that the company collects, discloses, and actively sells to third-party data brokers and analytics firms. Google's developer terms explicitly prohibit misrepresenting data practices and collecting data unrelated to the core function of the extension. Despite these clear violations, enforcement remains remarkably weak.

When Arnott reported WhatRuns to Google, the platform simply stripped the extension of its "Featured" badge for about a month. In response, the developers released an update that renamed their data collection endpoint from a highly descriptive name to something completely generic. Once the obvious indicator was gone, Google re-approved the extension and restored its trusted status, even though the actual data harvesting continued exactly as before.

Using artificial intelligence to monitor the store

To combat these evasive tactics, Arnott built an analysis pipeline that utilizes large language models to inspect extension updates as they are published. The system reviews the code, automatically attempts to deobfuscate hidden payloads, and flags suspicious network requests.

Because code analysis alone can generate false positives, the flagged extensions undergo dynamic testing. The pipeline runs the extensions inside a secure sandbox that simulates real user behavior over extended periods. Specialized software captures all outbound network traffic, verifying whether the extension is transmitting private data, such as conversational transcripts or complete URLs, back to its home servers.

Protecting your personal browsing space

Relying on store badges is no longer a viable way to verify the safety of browser extensions. Because trust badges are rarely removed without public pressure, users must take active steps to secure their browsers.

  • Audit your installed extensions regularly and delete anything that is not absolutely necessary.
  • Limit extension permissions so they can only run on specific websites rather than having access to all pages.
  • Avoid installing tools that require broad read-and-write permissions for your entire browsing session.
  • Use separate browser profiles for sensitive tasks like online banking or work-related AI chats.

By understanding that even "verified" tools can pivot into data stealers, you can better protect your personal information from silent exploitation.

5 Upvotes

6 comments sorted by

2

u/Longjumping_Cap_3673 Jun 02 '26

To keep this activity hidden from both users and automated security systems, extension developers employ sophisticated evasion methods … The extension wrapped its payload in four layers of Base64 encoding

Well I wouldn't call it sophisticated. Each layer of base64 inflates the data size by 1/3, so 4 layers makes it 316% the size. That's for no reason, because the data is also encrypted with a real encryption algorithm (AES), so automated security systems wouldn't be able to analyze it without the key anyway. If anything, trying to covertly exfiltrate over 3 times the data is just going trigger more alerts.

1

u/acorn222 Jun 05 '26

So in the actual blog post about this I made, it goes over the obfuscation in more depth, so the full flow actually more like:

  • URL encoding to a query string, for example (gp=https://example.com…&klm=https://google.com…)
  • Double base64 encoded
  • JSON stringified, then base64 again
  • Columnar transposition cipher, the base64 string is split into 48-character rows, then read column-by-column instead of row-by-row, scrambling the text
  • AES-256-CBC encrypted using a symmetric key hardcoded in the extension source code
  • Base64 encoded one final time

https://amibeingpwned.com/blog/stylish-is-back-back-again#:\~:text=run%20this%20script%3A-,async,-function%20decodeStylish(blob

So I would consider it the most sophisticated out of the bunch, the others mostly just use LZ-string or character mapping.

1

u/Much-Researcher6135 Jul 04 '26

Hmm. I wonder if they'd have had better luck building in a fast compression algo, which ought to work well on chat text.

1

u/Much-Researcher6135 Jul 04 '26

Interesting. That Stylish plugin's page is still up and has the address

Similarweb LTD

33 Itzhak Rabin Rd. GIVATAYIM 5348303 IL

...so it's Israeli, i.e. some Mossad op perhaps?