Browser extension AI chat exfiltration: Difference between revisions
Homelabber (talk | contribs) |
Homelabber (talk | contribs) |
||
| Line 81: | Line 81: | ||
===SimilarWeb=== | ===SimilarWeb=== | ||
SimilarWeb is the publisher of both the Stylish extension & an extension named after the company itself. Arnott documented both as Confirmed AI-chat exfiltrators, with the SimilarWeb-branded extension sending AI chats & full URLs even when the user is not interacting with it.<ref name="aibp-wall" /> Stylish has carried SimilarWeb's name as publisher since the company acquired the extension in January 2017; Robert Heaton documented in July 2018 that the post-acquisition version recorded every URL Stylish's two million users visited & sent those URLs to SimilarWeb's servers with a unique identifier.<ref name="heaton">{{Cite web |url=https://robertheaton.com/2018/07/02/stylish-browser-extension-steals-your-internet-history/ |title='Stylish' browser extension steals all your internet history |last=Heaton |first=Robert |date=July 2, 2018 |access-date=May 29, 2026}}</ref> Arnott separately observed a contradiction between the Stylish privacy policy, which he says explicitly states the company sells personal data, & the Chrome Web Store listing's larger-font claim on the home page that it does not.<ref name="aibp-stylish" /> As of May 2026 the Stylish Chrome Web Store listing names ''"Similarweb LTD"'' as the publisher, reports two million users & shows the Featured badge.<ref name="cws-stylish">{{Cite web |url=https://chromewebstore.google.com/detail/stylish-custom-themes-for/fjnbnpbmkenffdnngjfgmeleoegfcffe |title=Stylish - Custom themes for any website |work=Chrome Web Store |access-date=May 29, 2026}}</ref> It should be noted that SimilarWeb offers on their website Data-as-a-Service, allowing | SimilarWeb is the publisher of both the Stylish extension & an extension named after the company itself. Arnott documented both as Confirmed AI-chat exfiltrators, with the SimilarWeb-branded extension sending AI chats & full URLs even when the user is not interacting with it.<ref name="aibp-wall" /> Stylish has carried SimilarWeb's name as publisher since the company acquired the extension in January 2017; Robert Heaton documented in July 2018 that the post-acquisition version recorded every URL Stylish's two million users visited & sent those URLs to SimilarWeb's servers with a unique identifier.<ref name="heaton">{{Cite web |url=https://robertheaton.com/2018/07/02/stylish-browser-extension-steals-your-internet-history/ |title='Stylish' browser extension steals all your internet history |last=Heaton |first=Robert |date=July 2, 2018 |access-date=May 29, 2026}}</ref> Arnott separately observed a contradiction between the Stylish privacy policy, which he says explicitly states the company sells personal data, & the Chrome Web Store listing's larger-font claim on the home page that it does not.<ref name="aibp-stylish" /> As of May 2026 the Stylish Chrome Web Store listing names ''"Similarweb LTD"'' as the publisher, reports two million users & shows the Featured badge.<ref name="cws-stylish">{{Cite web |url=https://chromewebstore.google.com/detail/stylish-custom-themes-for/fjnbnpbmkenffdnngjfgmeleoegfcffe |title=Stylish - Custom themes for any website |work=Chrome Web Store |access-date=May 29, 2026}}</ref> It should be noted that SimilarWeb offers on their website Data-as-a-Service, allowing businesses to "Harness billions of data points from across the digital landscape to fuel business growth with Similarweb's Data-as-a-Service." <ref>{{Cite web |title=SimilarWeb Data-as-a-Service Solutions |url=https://www.similarweb.com/corp/daas/}}</ref> | ||
===Sensor Tower=== | ===Sensor Tower=== | ||