HomeSecurityChrome: Popular ad blocker extension allowed code injection

Chrome: Popular ad blocker extension allowed code injection

Analysis of a popular Chrome extension ad blocker, specifically designed for YouTube, showed that it had the ability to execute arbitrary JavaScript code.

Article Image: Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability

Popular ad blocker may put you at risk

According to Island, the extension, called Adblock for YouTube (ID: cmedhionkhpnakcndndgjdbohmhepckk), has more than 10 million installations and is Featured in the Chrome Web Store.

The extension's description states that it allows users to prevent ads from appearing on the video-sharing platform, as well as on external websites that load YouTube. While the plugin delivers the functionality it promises, it also has the potential to execute arbitrary JavaScript code.

This could mean reading pages, stealing data , and acting as a user within personal accounts, work applications, admin panels, and other sensitive browsing sessions.

See also: Chrome Extensions: 152 dangerous wallpaper add-ons with 105K installations

It is worth emphasizing here that there is no evidence of the malicious payload being distributed to users in this way, but the mere presence of the feature, combined with links to other ad-blocking extensionsthat have been removed from the store for malware, increases privacy and security risks.

The list of relevant extensions that have been removed includes:

– Adblock for Chrome (ID: onomjaelhagjjojbkcafidnepbfkpnee)

– Adblock for You (ID: ogcaehilgakehloljjmajoempaflmdci)

– AdBlock Suite (ID: gekoepiplklhniacchbbgbhilidiojmb)

Adblock for YouTube has been in the Chrome Web Store since 2014, starting out as a basic ad blocker for YouTube before changing ownership four years later. Early versions of the extension were found to include an ad-injection software development kit (SDK) called Unistream SDK, although it was removed in June 2024.

See also: Microsoft Edge: Testing Scareware Blocker to protect against tech support scams

Furthermore, the risk is increased by the fact that ad blocker extensions typically request extensive permissions to inspect requests, modify pages, hide elements, and adapt their behavior as ad systems evolve.

Chrome: Popular ad blocker extension allowed code injection

Specifically, it has been found that, contrary to its name, the extension works on every website the user visits in the browser, while adding a check that is only triggered when the current URL contains “yοutube.com”. However, in reality, the check only verifies whether the string corresponding to “yοutube.com” appears anywhere in the URL and does not validate the hostname, the context origin, or the embedded player context.

Selecting the team

🛡️ Block ads & trackers with NetShield

Proton VPN's NetShield filters ads, trackers, and malicious domains at the network level — across all applications, not just the browser.

  • ✔ Block ads & trackers everywhere on the device
  • ✔ Block malicious & phishing domains
  • ✔ Works on mobile & desktop — free trial
Activate NetShield for free →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

This means that the check can be easily bypassed by putting youtube.com anywhere in the URL, as illustrated in the following URL patterns:

– www.facebook.com/page?ref=youtube.com

– bank.example.com/search?q=yοutube.com

– internal.corp.com/redirect?from=youtube.com

See also: GlassWorm malware hides RAT in Chrome extension

This case is yet another reminder that even the most popular browser extensions should not be automatically considered safe. A large number of installs, a long-standing presence in the Chrome Web Store, or even a “Featured” label are no guarantee that an extension cannot acquire excessive permissions or incorporate features that could be abused in the future.

For cybersecurity experts, the incident highlights the need for users to regularly review the extensions they have installed on their browsers and limit the access permissions they grant to a minimum. In an era where the browser has become a central access point to banking services, corporate applications and personal data, even a seemingly innocent ad blocker can become a potential risk to users' privacy and digital security.

source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS