Content blockers usually use and load filters, which define what content on the siteswe visit will be blocked or changed in the web browser by default.
This needs to be done so that the default settings block unwanted content.
In most cases, extensions come with some custom and some proprietary filters. Users usually have the option to add their own filters as well.
Recently, a researcher discovered that some blockers, such as Adblock Plus, have a vulnerabilitythat could allow hackers to execute malicious code on sites visited by the victim.
The vulnerability is related to the $rewrite filter, which is present in Adblock Plus. The $rewrite filter is used to replace code on websites by rewriting it. The filter is designed to block content from third-party servers or sites.
However, the researcher discovered that there is a vulnerability in $rewrite, which allows hackers to load content from remote locations.
In order for someone to do this, 3 things must happen:
- A JavaScript string must have been loaded using XMLHttpRequest or Fetch and the return code must have been executed.
- There should be no restriction, e.g. using Content Security Policy directives, and the final URL cannot be validated before execution.
- The code must have an "open" redirect or host arbitrary user content.
Another thing that also needs to be done, for the attack, is to add a filter, which can be used by hackers, to the adblocker's filter list.
In many cases, users load filter lists into their extensions. These lists can be used by hackers for malicious purposes, although this does not happen very often.
It appears that certain extensions are vulnerable. For example, the uBlock Origin extension does not support $rewrite and is therefore not affected by the vulnerability.
