Connect with us

Technology

300,000 Chrome users hit by fake AI extensions

Published

on

300,000 Chrome users hit by fake AI extensions

NEWYou can now listen to Fox News articles!

Your web browser may feel like a safe place, especially when you install helpful tools that promise to make your life easier. But security researchers have uncovered a dangerous campaign in which more than 300,000 people installed Chrome extensions pretending to be artificial intelligence (AI) assistants. Instead of helping, these fake tools secretly collect sensitive information like your emails, passwords and browsing activity.

They used familiar names like ChatGPT, Gemini and AI Assistant. If you use Chrome and have installed any AI-related extension, your personal information may already be exposed. Even worse, some of these malicious extensions are still available today, putting more people at risk without their knowing.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

More than 300,000 Chrome users installed fake AI extensions that secretly harvested sensitive data. (Kurt “CyberGuy” Knutsson)

Advertisement

What you need to know about fake AI extensions

Security researchers at browser security company LayerX discovered a large campaign involving 30 malicious Chrome extensions disguised as AI-powered assistants (via BleepingComputer). Together, these extensions were installed more than 300,000 times by unsuspecting users.

Some of the most popular extensions included names like AI Sidebar with 70,000 users, AI Assistant with 60,000 users, ChatGPT Translate with 30,000 users, and Google Gemini with 10,000 users. Another extension called Gemini AI Sidebar had 80,000 users before it was removed.

These extensions were distributed through the official Chrome Web Store, which made them appear legitimate and trustworthy. Even more concerning, researchers found that many of these extensions were connected to the same malicious server, showing they were part of a coordinated effort.

While some extensions have since been removed, others remain available. This means new users could still unknowingly install them and expose their personal data. Here’s the list of the affected extensions:

  • AI Assistant
  • Llama
  • Gemini AI Sidebar
  • AI Sidebar
  • ChatGPT Sidebar
  • Grok
  • Asking ChatGPT
  • ChatGBT
  • Chat Bot GPT
  • Grok Chatbot
  • Chat With Gemini
  • XAI
  • Google Gemini
  • Ask Gemini
  • AI Letter Generator
  • AI Message Generator
  • AI Translator
  • AI For Translation
  • AI Cover Letter Generator
  • AI Image Generator ChatGPT
  • Ai Wallpaper Generator
  • Ai Picture Generator
  • DeepSeek Download
  • AI Email Writer
  • Email Generator AI
  • DeepSeek Chat
  • ChatGPT Picture Generator
  • ChatGPT Translate
  • AI GPT
  • ChatGPT Translation
  • ChatGPT for Gmail

FAKE AI CHAT RESULTS ARE SPREADING DANGEROUS MAC MALWARE

These malicious tools were listed in the official Chrome Web Store, making them appear legitimate and trustworthy. (LayerX)

Advertisement

How the fake AI Chrome extension attack works

These fake extensions pretend to offer helpful AI features, such as translating text, summarizing emails, or acting as an AI assistant. But behind the scenes, they quietly monitor what you are doing online.

Once installed, the extension gains permission to view and interact with the websites you visit. This allows it to read the contents of web pages, including login screens where you enter your username and password.

In some cases, the extensions specifically targeted Gmail. They could read your email messages directly from your browser, including emails you received and even drafts you were still writing. This means attackers could access private conversations, financial information and sensitive personal details.

The extensions then sent this information to servers controlled by the attackers. Because they loaded content remotely, the attackers could change their behavior at any time without needing to update the extension.

Some versions could also activate voice features through your browser. This could potentially capture spoken conversations near your device and send transcripts back to the attackers.

Advertisement

If you installed one of these extensions, attackers may already have access to extremely sensitive information. This includes your email content, login credentials, browsing habits and possibly even voice recordings.

We reached out to Google for comment, and a spokesperson told CyberGuy that the company “can confirm that the extensions from this report have all been removed from the Google Web Store.”

BROWSER EXTENSION MALWARE INFECTED 8.8M USERS IN DARKSPECTRE ATTACK

Once installed, the extensions could read emails, capture passwords, monitor browsing activity and send the data to attacker-controlled servers. (Bildquelle/ullstein bild via Getty Images)

7 ways you can protect yourself from malicious Chrome extensions

If you have ever installed an AI-related Chrome extension, taking a few simple precautions now can help protect your accounts and prevent further damage.

Advertisement

1) Remove any suspicious or unused browser extensions

On a Windows PC or Mac, open Chrome and type chrome://extensions into the address bar. Review every extension listed. If you see anything unfamiliar, especially AI assistants you don’t remember installing, click “Remove” immediately. Malicious extensions depend on going unnoticed. Removing them stops further data collection and cuts off the attacker’s access to your information.

2) Change your passwords

If you installed any suspicious extension, assume your passwords may be compromised. Start by changing your email password first, since email controls access to most other accounts. Then update passwords for banking, shopping and social media accounts. This prevents attackers from using stolen credentials to break into your accounts.

3) Use a password manager to create and protect strong passwords

A password manager generates unique, complex passwords for each account and stores them securely. This prevents attackers from accessing multiple accounts if one password is stolen. Password managers also alert you if your login credentials appear in known data breaches, helping you respond quickly and protect your identity. Check out the best expert-reviewed password managers of 2026 at Cyberguy.com.

4) Install strong antivirus software and keep it active

Good antivirus software can detect malicious browser extensions, spyware, and other hidden threats. It scans your system for suspicious activity and blocks harmful programs before they can steal your information. This adds an important layer of protection that works continuously in the background to keep your device safe. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com.

5) Use an identity theft protection service

Identity theft protection services monitor your personal data, including email addresses, financial accounts, and Social Security numbers, for signs of misuse. If criminals try to open accounts or commit fraud using your information, you receive alerts quickly. Early detection allows you to act fast and limit financial and personal damage. See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com.

Advertisement

6) Keep your browser and computer fully updated

Software updates fix security vulnerabilities that attackers exploit. Enable automatic updates for Chrome and your operating system so you always have the latest protections. These updates strengthen your defenses against malicious extensions and prevent attackers from taking advantage of known weaknesses.

7) Use a personal data removal service

Personal data removal services scan data broker websites that collect and sell your personal information. They help remove your data from these sites, reducing what attackers can find and use against you. Less exposed information means fewer opportunities for criminals to target you with scams, identity theft or phishing attacks.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

Kurt’s key takeaway

Even tools designed to make your life easier can become tools for cybercriminals. Malicious extensions often hide behind trusted names and convincing features, making them difficult to spot. You can significantly reduce your risk by reviewing your browser extensions regularly, removing anything suspicious and using protective tools like password managers and strong antivirus software.

Advertisement

Have you checked your browser extensions recently? Let us know your thoughts by writing to us at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Copyright 2026 CyberGuy.com. All rights reserved.

Advertisement

Related Article

Malicious browser extensions hit 4.3M users

Technology

Govee’s new LED Lightwall comes with its own self-standing frame

Published

on

Govee’s new LED Lightwall comes with its own self-standing frame

Govee has announced an upgraded version of its hanging Curtain Lights Pro that can instead be used nearly anywhere you have access to an outlet or large battery. At $449.99, Govee’s new Lightwall is more than twice as expensive as the $199.99 Curtain Lights Pro, but comes with more LEDs in a denser array and a self-standing aluminum frame that can be assembled in 10 to 15 minutes without the need for any tools.

When hung from its stand the Lightwall measures 7.9 feet wide and 5.3 feet tall and features 1,536 color-changing LEDs spaced about 1.96 inches apart in a 48 x 32 grid. It’s water-resistant, and with the ability to refresh at up to 35fps the Lightwall almost sounds like it could be used as a personal backyard Jumbotron, but it’s not designed for watching TV or movies.

The Lightwall instead connects to Govee’s Home app where you can select from over 200 preset scenes and simple animations, choose from 10 different music modes that generate lighting patterns matched to beats, or synchronize its colors to other Govee lighting products to create a cohesive mood.

The app can also use AI to create custom animated GIFs from simple text prompts, or you can take matters into your own hands and create custom designs by sketching in the app with your finger and stacking up to 30 layers of doodles. The Lightwall is smart home compatible and supports Matter, too, so in addition to managing it through Govee’s app you can control it using voice commands through smart devices with Google Assistant or Amazon Alexa.

Continue Reading

Technology

Roblox adds age-based accounts for kids and teens

Published

on

Roblox adds age-based accounts for kids and teens

NEWYou can now listen to Fox News articles!

If your child plays Roblox, they are part of a massive global audience. Roblox has reported more than 144 million daily active users, with a large share made up of kids and teens who log in to play games, create content and connect with friends. That reach is exactly why a new change rolling out in early June matters.

Advertisement

Roblox is introducing two new account types designed to better match what kids play and who they can talk to based on age. The shift centers on structure. Instead of one shared experience with layered controls, Roblox is building separate environments for different age groups. As a result, content, chat and parental controls will adjust automatically as a child grows.

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

OPENAI TIGHTENS AI RULES FOR TEENS BUT CONCERNS REMAIN

Roblox rolls out a new AI system that analyzes entire scenes in real time to detect harmful content across its platform. (Brent Lewin/Bloomberg via Getty Images)

 

What are Roblox Kids and Roblox Select accounts?

Roblox is dividing younger users into two groups, each with its own rules and experience.

Roblox Kids (ages 5 to 8)

This is the most restricted environment. It is designed for younger children who need tighter guardrails.

Advertisement
  • Access limited to games rated Minimal or Mild
  • Only games that pass a three-step review process
  • Chat is turned off by default
  • A distinct visual design so parents can easily recognize the account

The idea here is simple. Kids see a limited version of Roblox that removes riskier content and disables communication.

Roblox Select (ages 9 to 15)

AUSTRALIA REMOVES 4.7M KIDS FROM SOCIAL MEDIA PLATFORMS IN FIRST MONTH OF HISTORIC BAN

This group gets more flexibility, but still within limits.

  • Access to games rated up to Moderate
  • Same multi-step game screening process
  • Chat settings remain on by default in most regions
  • Visual indicators show the account type

At this stage, Roblox assumes users can handle a broader range of experiences, but still keeps filters in place.

How Roblox decides what games kids can play

Not every game makes the cut. Roblox is adding a continuous evaluation system that runs behind the scenes. Here’s how it works:

1) Developer verification

Creators must verify their identity, enable two-step security and maintain a Roblox Plus subscription.

2) Real-time evaluation

Older users, age 16 and up, effectively test new games first. Roblox studies how they interact and reviews reports before exposing those games to younger players.

Advertisement

3) Content eligibility check

Games receive maturity ratings such as Minimal, Mild or Moderate. Certain categories, like social hangouts or free-form drawing, are excluded by default for younger users. This layered approach combines AI moderation, human review and real-world gameplay signals.

Age checks now control the entire experience

Roblox is expanding the same age-check system it introduced earlier this year for chat.

  • Users under 9 Roblox Kids
  • Users 9 to 15 Roblox Select
  • Users 16 and older standard with Roblox account

If a user does not complete an age check, they face stricter limits. They can only access lower-rated games and cannot use chat. Once verified, the system automatically moves them into the correct account type.

Roblox officials say the new system aims to proactively protect children while maintaining gameplay for compliant users. (Riccardo Milani/Hans Lucas/AFP via Getty Images)

 

Accounts evolve as kids grow

There is no need to manually switch settings over time.

  • At age 9, users move from Kids to Select
  • At age 16, they move to a standard account

This automatic progression is designed to simplify things for families while keeping protections in place at each stage.

Parental controls get more precise

Roblox is also expanding what parents can do.

Advertisement
  • Block specific games through age 15
  • Manage direct chat settings until age 15
  • Approve access to individual games outside default limits
  • View what games kids play and who they interact with

These tools give parents more direct control instead of relying only on broad content filters.

A move toward global content ratings

Later this year, Roblox plans to align with the International Age Rating Coalition framework. That includes familiar systems like ESRB in the U.S. and PEGI in Europe. The goal is to make ratings clearer and more consistent across regions. 

Why this matters to families

This update changes how Roblox works at a fundamental level. Instead of asking parents to constantly adjust settings, the platform builds age-appropriate experiences from the start. It also reflects a broader shift in tech. Platforms are under pressure to design safety into the product, not tack it on later.

As Larry Magid, CEO of ConnectSafely, an organization focused on helping families navigate digital safety, put it:

“By combining age assurance, stronger creator accountability, and parental controls, Roblox is helping set a higher standard for how platforms can better protect younger users while preserving positive online experiences.”

Take my quiz: How safe is your online security?

Think your devices and data are truly protected? Take this quick quiz to see where your digital habits stand. From passwords to Wi-Fi settings, you’ll get a personalized breakdown of what you’re doing right and what needs improvement. Take my Quiz here: Cyberguy.com.

Advertisement

Kurt’s key takeaways

Roblox targets nuanced rule-breaking by analyzing avatars, text and environments together instead of in isolation. (JasonDoiy/Getty Images)

Roblox is not removing risk entirely. No platform can. What it is doing is tightening the structure around how kids interact with content and other players. For parents, this could make things simpler. For kids, the experience will feel more tailored to where they are in life. The bigger question is whether this becomes the norm across gaming and social platforms.

If platforms start shaping experiences based on age by default, does that improve safety or limit how kids explore and learn online? Let us know by writing to us at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report

Advertisement
  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

Copyright 2026 CyberGuy.com. All rights reserved.  

Continue Reading

Technology

YouTube now lets you turn off Shorts

Published

on

YouTube now lets you turn off Shorts

YouTube’s time management settings now have an option to put a zero-minute time limit on Shorts, effectively removing them from your app in Android and iOS. The option is an update to the Shorts timer YouTube originally announced in October; the lowest previous option was 15 minutes.

The feature was expanded in January to give parents some control over how long their kids spend scrolling through Shorts, with an option for zero minutes “coming soon.” According to YouTube spokesperson Makenzie Spiller, the option to set the timer to zero is now “live for all parents, and is currently being rolled out to everyone,” including users with regular adult accounts.

Regardless of age, it can be a handy tool for anyone who wants to spend a little less time scrolling. The Shorts tab won’t show any videos once you hit your limit, just a notification that you’ve “reached your Shorts feed limit.” In our tests, hitting the time limit also removes Shorts from the Home screen, so by setting the timer to zero you can ignore Shorts entirely if you want. To turn on the timer, go to the settings in the YouTube app and select “time management” then toggle on the Shorts feed limit and select a time for it.

Continue Reading
Advertisement

Trending