Researchers at Bay Area Labs report that Poper Blocker, a pop-up blocking browser extension with over 2 million users, collects full browsing history and conversations from ChatGPT, Claude, Gemini and Google's AI Mode once users accept a data-sharing prompt [2]. The analysis was published on the AmIBeingPwned site and summarised by SecurityWeek on 2 October 2026 [1] [2]. The report is relevant to Mac users because the analysis lists Safari among the browsers the extension supports.
Background
Browser extensions run inside the browser and can read the pages a user opens. An AI chat in a browser tab is a web page, so an extension with broad page access can in principle read it. The analysis describes Poper Blocker as an extension for Chrome, Edge and Safari that claims to block pop-ups [1].
Findings
SecurityWeek quotes the research as stating that the collection logic is downloaded from the vendor's server and run by a custom interpreter inside the extension, so the operator can change what is collected, and where it is sent, without pushing an update [2]. The analysis states that the programs come from api.pbapi.xyz, are written in a custom scripting language, and arrive obfuscated, with commands referenced by numbers mapped to a server-side dictionary [1].
According to the analysis, the extension sends full browsing URLs with referrers and query parameters, AI chat conversations from ChatGPT, Claude and Gemini, social media data from Facebook, Instagram, LinkedIn and X, a cross-device identifier, and browser fingerprints [1]. It states that 23 of the 40 programs it examined target AI platforms [1].
The analysis reports that the extension fingerprints the browser to recognise automated review environments, and that the programs do not load for about 24 hours after installation, which it presents as a likely attempt to evade Google's review sandbox [1]. It also reports that a persistent pop-up states that data sharing is required for advanced blocking features, and that the privacy policy contains an opt-out toggle that functions as an opt-in [1].
The analysis states that the issue was reported to Google in May 2026 and that the extension remained featured on the Chrome Web Store, with a verified publisher badge and a 4.8-star rating from more than 81,600 reviews [1]. It adds that uninstalling still leaks data: the last five visited domains are base64-encoded into an uninstall URL parameter sent to poperblocker.com [1].
Implications for Mac users
Most Mac users who use AI assistants in a browser type personal or work material into them. The analysis indicates that, for users who accepted the data-sharing prompt, that material was within the reach of the extension's collection programs [1] [2]. The sources do not state how many of the extension's users are on Safari or on a Mac.
The design also limits what a one-time review can establish. Because the collection programs are downloaded, the behaviour seen on a given day can differ from the behaviour a store reviewer or a user saw earlier [1] [2].
Recommendations
- Open the extension list of each browser in use (Chrome, Edge, Safari) and check whether Poper Blocker is installed.
- Remove extensions that are not needed, and keep to those whose publisher and permissions are understood.
- Decline data-sharing prompts that describe sharing as required for a blocking feature.
- Treat anything typed into an AI chat while the extension was active as possibly seen by its operator, and change any password or key that was pasted into a chat.
- Review the destinations the browser contacts, and look for names the user does not recognise.
Relevance to FireAI
FireAI is a firewall for one Mac. It identifies an app by its code signature and applies per-app rules to each connection that app opens; the Activity page lists the apps that went online, newest first. A browser appears in that list as one app, so a rule can block one domain for the browser, for example a domain the user has found in an extension analysis.
FireAI does not see inside a browser, so it cannot tell which extension made a connection, and it does not list, scan or remove extensions. It does not read the content of an encrypted connection or of a chat, and it does not know whether a transfer contains a conversation. A rule that blocks a domain for a browser applies to everything the browser sends there, and it does not undo what an extension collected before the rule existed.
Limitations
The claims about collection come from one research analysis, summarised by SecurityWeek; this item did not reproduce the analysis or install the extension [1] [2]. The sources, as fetched, contain no response from the extension's vendor, and they do not say whether the Safari version behaves like the Chrome version. They also do not state the current status of the extension in each store.
Try FireAI, by HisnLabs free for 17 days.