Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomePicsee - Photo Browse & Manage
Findings · 2
LOW FINDINGS · 2
  1. 01Sends user-selected page media (image/video src, title, page URL, meta tags) plus full-page screenshots to local Picsee.app HTTP server on 127.0.0.1:42698; content script runs on <all_urls> but exfil only triggers on explicit user action (context menu, drag, keyboard shortcut)
  2. 02Local IPC to Picsee.app uses cleartext HTTP on 127.0.0.1:42698 rather than a Safari native-messaging XPC channel; payload includes page URL/title and image content but stays on loopback so cross-network exposure is nil
OTHER EXTENSIONS

Is Picsee - Photo Browse & Manage safe?

Low risk

No summary available.

志泉 孔v1.7.8Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026me.zhiquan.mac.Picsee.PicseeSafari

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact