YouTube ad-blocker could take control of any website

June 26, 2026  22:56

Cybersecurity researchers have discovered a potentially dangerous feature in one of the most popular Google Chrome extensions designed to block ads on YouTube. We are talking about the "Adblock for YouTube" extension (ID: cmedhionkhpnakcndndgjdbohmhepckk), which has over 10 million installations and holds a "Featured" badge in the Chrome Web Store, as reported by The Hacker News. 

According to Island, despite its stated functionality of blocking ads on YouTube and third-party websites that use the platform's embedded video players, the extension contains mechanisms that allow the execution of arbitrary JavaScript code.

The dangerous capability is hidden within the extension's architecture

Island specialists Oleg Zaitsev and Shahar Grizman emphasize that the issue is not the detection of active malware, but rather the very architecture of the extension.

According to them, the extension contains all the necessary components to execute arbitrary JavaScript on any website. Activating this capability requires just a single configuration change on the server side. In doing so, users will not need to install an extension update, and the modification itself will skip the Chrome Web Store review process and go unnoticed by any visible signs.

Researchers warn that such a mechanism could theoretically be used to read web page content, steal data, and perform actions on behalf of the user in personal accounts, enterprise applications, administrative panels, and other sensitive web services.

It is important to note that, as of now, there is no evidence that this capability has actually been used to distribute malicious payloads to users. However, the mere presence of such functionality raises serious questions regarding security and privacy.

Traces of past changes and links to removed extensions

The history of the project's development raises additional concerns among specialists. The extension has been present in the Chrome Web Store since 2014. Initially, it was a simple tool for blocking ads on YouTube. However, four years later, the project changed ownership.

Early versions of the extension contained the Unistream SDK, designed for ad injection. This component was only removed in June 2024.

Furthermore, researchers found that starting from February 2025, mechanisms for remotely controlled script injection have been continuously present in the extension. These allow the creation of arbitrary <script> elements using a custom rule called trusted-create-element, developed by the extension's author.

During the analysis, this mechanism was not activated by the server. Nevertheless, experts emphasize that it remains accessible and can be enabled without releasing a new version of the extension. "At the time of our analysis, the trusted-create-element feature was not active in the server response. This capability is not absent; it is in a dormant state. Activating it requires just a single server-side change, with no extension updates and no store review," the researchers note.

The situation is further aggravated by the fact that this project is linked to other ad-blocking extensions that were previously removed from the Chrome Web Store after malicious activity was detected.

Experts point to a combination of risk factors

Island emphasizes that the problem is not limited to a single suspicious line of code.

Anxiety is driven by a combination of several circumstances at once: a massive user base, access to all visited websites, the capability for remote script injection, a history of using ad-serving infrastructure, significant changes in ownership and the project's codebase, as well as connections to other extensions previously removed from the Google store for malicious activity.

At the time of publication, the developer of Adblock for YouTube had not commented on the research findings.

Another threat: extensions masquerading as well-known brands

In a parallel development, Palo Alto Networks Unit 42 specialists reported the identification of 18 browser extensions masquerading as products of well-known consumer brands.

The primary goal of these extensions was monetization through affiliate programs.

Once installed, these add-ons automatically opened websites in the .shop domain zone. Users were then redirected to other resources, where they were notified of alleged compatibility issues. Subsequently, they were prompted to install a gaming-oriented browser.

While such a scheme appears relatively harmless compared to the direct distribution of malware, it demonstrates how actively threat actors use browser extensions for monetization and user manipulation.

In brief

Island's research has revealed a hidden capability in the popular Adblock for YouTube extension to remotely trigger the execution of arbitrary JavaScript code without updating the extension or undergoing a Chrome Web Store re-review. While there is no evidence of actual abuse of this feature yet, the presence of such a mechanism poses severe risks to user security.

Of particular concern is the combination of several factors: over 10 million installations, access to all websites, remote control mechanisms, a history of using ad SDKs, and links to other extensions previously removed for malicious activity. This situation once again raises the question of how carefully users and platforms should approach the security of browser extensions, even when they appear harmless and enjoy immense popularity.


 
 
 
 
  • Archive