Earlier quoted context omitted.
It can be more sinister. Although I am sure the other answers are right in some circumstances, I was curious a while ago, so I actually clicked one. Whether you click allow or deny, it shot off a network request to a third party domain. This lets the third party know your browser's user agent, and if they have an exploit for your browser they will send a payload that compromises the browser with the intent of install…
But any click can do that, right? No need for it to be a fake Allow/Deny prompt. The best I can think of is that it does 2 things: 1. Preserves the "true" allow/deny prompt for a time when the user will allow. 2. Lulls the user into a sense of security. The page is nice and/or their browser will ask about anything the page tries to do.
It also needs to seem legitimate so people click it but don't report it.