Back to News
Threat Intelligence

Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability

Cyber RTJune 25, 20263 min read
Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability

An analysis revealed that the popular "Adblock for YouTube" Chrome extension, with over 10 million installs, can execute arbitrary JavaScript code, posing privacy and security risks. Although no malicious payloads have been detected, the extension's ability to inject scripts remotely without updates is concerning. The extension, initially a basic ad blocker, has evolved, maintaining script injection paths since 2025, raising potential security threats.

An analysis conducted by Island has revealed that a popular Google Chrome extension, Adblock for YouTube, has the capability to execute arbitrary JavaScript code. This extension, which boasts over 10 million installations and a Featured badge on the Chrome Web Store, is designed to block ads on YouTube and other sites that load YouTube content. While it performs its primary function effectively, it also possesses the ability to run arbitrary JavaScript code, raising significant security concerns. Researchers Oleg Zaytsev and Shachar Gritzman highlighted that the extension contains architectural elements that allow for the execution of arbitrary JavaScript on any website. This capability can be activated through a server-side configuration change without requiring an extension update or store review, and without any visible indication to users. Such a feature could potentially enable malicious activities like reading web pages, stealing data, and impersonating users in sensitive browser sessions. Although there is currently no evidence that this capability has been exploited to deliver malicious payloads, the mere existence of such a feature, especially given the extension's ties to other ad-blocking extensions removed for malware, poses privacy and security risks. Island noted that several related extensions have already been taken down from the Chrome Web Store due to similar concerns. Adblock for YouTube has been available on the Chrome Web Store since 2014. Initially, it served as a basic ad blocker for YouTube, but it underwent a change in ownership in 2018. Early versions included an ad-injection SDK, which was removed in mid-2024. However, since February 2025, the extension has maintained remote-controlled script injection paths, allowing the creation of arbitrary script elements that can access sensitive data. The researchers found that the extension's "trusted-create-element" feature, although dormant at the time of analysis, could be activated with a simple server-side change. This feature does not require an extension update or store review, further exacerbating the potential risk. Ad blocker extensions typically request extensive permissions, which can be exploited if such capabilities are activated. Moreover, the extension operates on every website a user visits, not just YouTube. It includes a check that activates when the URL contains "youtube.com," but this check is easily bypassed by including the string "youtube.com" anywhere in the URL. This oversight allows the extension to potentially execute its capabilities on non-YouTube sites, increasing the risk of misuse. Island emphasized that the issue is not just a single suspicious line of code but a combination of factors: a high-install extension with all-site access, a remote-controlled injection path, previous ad-injection infrastructure, significant ownership and codebase changes, and connections to other extensions removed for malware. The Hacker News has reached out to the extension's developer for comments on these findings. This disclosure coincides with a report from Palo Alto Networks Unit 42, which identified 18 browser extensions impersonating consumer brands to monetize through affiliate marketing. These extensions redirect users to a .shop domain upon installation, which then prompts users to install a gaming-oriented browser, citing compatibility issues. The ongoing scrutiny of browser extensions underscores the importance of vigilance in the digital ecosystem.