Two Chrome extensions have been identified as malicious, actively stealing conversations from users of OpenAI's ChatGPT and DeepSeek AI, according to cybersecurity researchers. The extensions, boasting a combined user base exceeding 900,000, represent a significant breach of privacy and security, highlighting the persistent risks associated with browser extensions.

Scope of the Breach: ChatGPT, DeepSeek, and Your Data

The compromised extensions, specifically one named 'Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI' are designed to exfiltrate user conversations directly to attacker-controlled servers. This not only exposes sensitive intellectual property and personal data shared within these chats but also potentially compromises browsing history and other sensitive information accessible to the extension. The attack surface presented by browser extensions remains a significant concern, with threat actors consistently finding new ways to exploit user trust.

The implications of this data exfiltration are far-reaching. Consider the potential for corporate espionage if proprietary information discussed within ChatGPT is leaked. Or the risk to individuals who use these platforms for sensitive personal matters. The CVSS score for such a vulnerability, considering the widespread impact and potential for significant data loss, would likely be in the critical range.

Modus Operandi: A Growing Threat Landscape

This incident underscores a growing trend: the weaponization of seemingly innocuous browser extensions. Users often grant broad permissions to extensions without fully understanding the potential risks. Once installed, these malicious extensions can operate with near-impunity, silently collecting data and transmitting it to external servers. This particular campaign highlights the importance of rigorous security audits and user awareness programs. Furthermore, as Dark Reading reports, threat actors are also using social engineering techniques to deploy remote access trojans, showcasing the multi-faceted nature of modern cyberattacks. "According to The Hacker News, the extensions are designed to exfiltrate OpenAI ChatGPT and DeepSeek conversations alongside browsing data to servers under the attackers' control," demonstrating the direct threat to user privacy.

Recommendations and Future Outlook

Users of 'Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI' should immediately uninstall the extension and review their ChatGPT and DeepSeek conversations for any potentially compromised data. As always, exercise extreme caution when installing browser extensions, and carefully review the permissions requested. The Chrome Web Store needs more robust security checks and user-reporting mechanisms. Looking ahead, we can anticipate an increase in sophisticated attacks targeting browser extensions. Developers and security researchers must collaborate to proactively identify and mitigate these threats. The incident serves as a stark reminder that even seemingly convenient tools can pose significant security risks. Mitigation strategies should include stricter permission controls for browser extensions and enhanced user education regarding the potential dangers.