amibeingpwned.com Poper Blocker Ad-Blocker Found to Exfiltrate User Data
Article Content
- •Poper Blocker has over 2 million downloads and is rated 4.8 stars.
- •The extension collects extensive user data, including browsing history and AI chat logs.
- •Google has not acted on reports of Poper Blocker's malicious behavior despite prior warnings.
Poper Blocker, an ad-blocking browser extension available on the Chrome Web Store, has been reported to exfiltrate sensitive user data, including browsing history and AI chat interactions. The extension, which claims over 2 million active users and has a 4.8-star rating, has been flagged by researchers at Bay Area Labs for employing malware techniques such as code obfuscation and sandbox evasion. Despite being reported to Google in May 2026, no action has been taken against it. The app's data collection practices violate Chrome Web Store policies, which prohibit the collection of browsing data without explicit user consent. Users are potentially exposed to significant privacy risks as the app can also take screenshots and gather detailed information about their online activities. This incident highlights the ongoing issue of malicious extensions masquerading as legitimate applications in popular app stores.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Poper Blocker and Bay Area Labs in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What data does Poper Blocker collect?
Has Google taken action against Poper Blocker?
How can users protect themselves from such extensions?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…