Security · 2h ago
Chrome Ad Blocker with 10M+ Installs Had Hidden Script Injection
A Chrome extension called Adblock for YouTube, with over 10 million installs and a Featured badge, was found capable of injecting arbitrary JavaScript code. Security firm Island discovered the dormant script injection capability in the extension. The extension remains available on the Chrome Web Store despite the risk.
Meridian48 take
This highlights how even popular, featured extensions can harbor hidden risks, underscoring the need for better vetting in Chrome's Web Store.
Read the full reporting
Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability →
The Hacker News
chrome-extensionad-blocker