Safety guide
Are AI browser extensions safe? Every major incident since 2023, and a 9-point check
AI extensions can read the pages you visit, including your email and your AI chats. Most are fine. Some have stolen accounts and conversations from millions of people — and a few of those had Google’s “Featured” badge. Here’s the record and how to protect yourself.
The extension itself is the risk, not AI. An extension that can “read and change data on all websites” can read your AI chats, email and banking. Prefer the AI company’s own extension, check the publisher, permissions and privacy box, and remove what you don’t use. A Featured badge is a good sign, not proof.
The official AI extensions (October 2026)
| Product | What it does | Who can use it |
|---|---|---|
| ChatGPT extension | Chat next to any page, bring open tabs into ChatGPT, and let it act on sites where you’re signed in. Works through the ChatGPT desktop app | Chrome, Edge, Brave, Opera, Vivaldi; rolling out by plan |
| Claude in Chrome | Reads the page, then clicks, types and fills forms for you | Paid Claude plans; desktop Chrome only |
| Gemini in Chrome | Built into Chrome, no install. Side panel and connected Google apps; “auto browse” agent | Free; auto browse needs Google AI Pro or Ultra |
| Copilot in Edge | Built into Edge since Copilot Mode was folded in on May 13, 2026 reported | Free with a Microsoft account |
| ChatGPT Atlas | OpenAI’s browser — shut down on August 9, 2026 | — |
What has gone wrong (newest first)
| When | What happened | Scale |
|---|---|---|
| Aug 2026 | “AI Sidebar with DeepSeek, ChatGPT, Claude and more”, removed by Google in January, reappeared in the store running affiliate-redirect code (Netskope) | 300,000+ installs before removal |
| Jun 2026 | Researchers reported flaws in the Sider and MaxAI extensions that could let a malicious website act in your logged-in sessions; the report said Sider hadn’t responded at the time | Millions of installs |
| Apr 2026 | Palo Alto Networks’ Unit 42 found 18 high-risk “AI productivity” extensions, including remote-access trojans and API-key theft | 18 extensions |
| Feb 2026 | LayerX found 30+ fake AI-assistant extensions sharing one backend, scraping pages and Gmail and stealing logins (e.g. “Gemini AI Sidebar”, “ChatGPT Translate”); removed | About 260,000–300,000 users |
| Dec 2025 | Urban VPN Proxy (6M users, Featured) and seven sister extensions were found collecting ChatGPT, Claude and Gemini conversations after a silent update, with no opt-out (Koi Security) | 8M+ users |
| Dec 2025 | Two copycat extensions stole full ChatGPT and DeepSeek chats every 30 minutes; one had the Featured badge (OX Security) reported | 900,000 users |
| Dec 2024 | Phishing hijacked about 35 extensions’ developer accounts, including AI ones like “ChatGPT for Google Meet”, to push malicious updates reported | About 2.6M users |
| Mar 2023 | A fake “Quick access to Chat GPT” extension hijacked Facebook business accounts (Guardio) reported | About 2,000 installs a day |
The badge problem
Google says a Featured badge means an extension was manually reviewed for good practice and privacy, and that nobody can pay for it. But a badge describes the extension at review time. Extensions update themselves automatically, and in several cases above a clean, badged extension started collecting data after an update or a change of owner. Treat the badge as a good sign, then keep checking.
Nine checks before you install
- Official store only, and check the publisher. OpenAI, Anthropic and Google don’t publish extensions called “ChatGPT Translate” or “Gemini AI Sidebar”.
- Prefer the AI company’s own extension over “all models in one” wrappers, which pass your text through a middleman.
- Read the permission prompt. “Read and change all your data on all websites” means it can see your AI chats, email and banking.
- Read the “Privacy practices” box on the store page. Be wary of data types it doesn’t need, like financial information or personal communications.
- Badges are a floor, not proof (see above).
- Check the history: a new developer name, or a sudden update after a long quiet spell, is a warning sign.
- Turn on Enhanced Safe Browsing in Chrome — it warns about untrusted extensions — and run Safety Check, which flags extensions removed as malware.
- Set site access to “On click” for extensions that don’t need to run everywhere.
- Remove what you don’t use. Every extension is a door.
AI browsers and agents that click for you
Agent features — Claude in Chrome, Gemini’s auto browse, Perplexity’s Comet browser, ChatGPT’s browser control — add a different risk: hidden instructions on a web page can steer the AI. Brave’s researchers showed near-invisible text in a screenshot could hijack Comet and called the problem “systemic”. Anthropic reports its defenses cut attack success in its hardest tests to between 0% and 0.3% depending on the model, from 23.6% before any protections in early testing — big progress, but not zero.
Use agents in a separate browser profile without your bank or email logins, keep confirmations switched on for anything that buys, sends or deletes, and don’t let an agent loose on sites you don’t trust.
Wondering about a specific extension? Read Is Sider safe? Is Monica safe? For connectors inside ChatGPT and Claude, see is MCP safe.
Sources: OpenAI: ChatGPT browser extension · OpenAI: Atlas shutdown · Anthropic: Claude in Chrome · Anthropic: Claude in Chrome GA · Anthropic: pilot results · Google: Gemini auto browse · SecurityWeek (AI Sidebar return) · Forever Security: Spyder and MaXSS · Unit 42 · BleepingComputer (LayerX AiFrame) · Infosecurity Magazine (Urban VPN) · OX Security · The Hacker News (Cyberhaven campaign) · Guardio · Brave: unseeable prompt injections · Chrome Web Store: badges · Chrome Safety Check
Quick answers
Are AI Chrome extensions safe?
Many are, but extensions are one of the most common ways AI chats and accounts get stolen. Since 2023, fake or compromised AI extensions have affected millions of users. Use the AI company’s own extension where possible, check the publisher and permissions, and remove extensions you don’t use.
Can a Chrome extension read my ChatGPT conversations?
Yes, if it has permission to read and change data on the sites you visit. Security researchers showed in 2025 that any extension with page access can read or rewrite prompts in ChatGPT, Gemini, Claude, Copilot and DeepSeek, and in December 2025 one VPN extension with 6 million users was found collecting AI conversations.
Does a Featured badge mean an extension is safe?
No. Google says Featured means the extension was manually reviewed for good practice and privacy, but it reflects the extension when it was reviewed. Several extensions later found harvesting data had the badge, because an automatic update changed their behavior.
What are the official AI extensions?
ChatGPT’s browser extension (it works through the ChatGPT desktop app), Claude in Chrome (paid Claude plans), and Gemini in Chrome, which is built into Chrome. Microsoft’s Copilot features are built into Edge.
Are AI browsers like Comet safe?
They add a new risk: hidden instructions on web pages can steer the AI. Brave’s researchers called this a systemic problem, and Anthropic says the risk isn’t zero even with its defenses. Use a separate browser profile without your bank or email logins for agent tasks, and keep confirmations on.
Keep learning
Is Sider safe? Is Monica safe? What the two biggest AI sidebars collect
Sider and Monica are top-rated AI Chrome extensions. Who owns them, what their store pages say they collect, a 2026 security report and safer options.
What is MCP, and is it safe to connect your apps to AI?
MCP is the plug that lets ChatGPT, Claude, Gemini and Copilot use your apps. What it is, how it differs from connectors, real incidents, and a safety checklist.
Plugins, skills, apps, connectors: what each one is in ChatGPT, Claude, Gemini and Copilot
ChatGPT plugins vs skills, connectors vs apps, Claude connectors vs MCP, Gems vs skills: one plain-English decoder for 2026, with the dates each name changed.