Adblock Plus and other ad blockers have a worrying security hole

Adblock Plus screen grab
Image credit: Adblock Plus

There’s a serious vulnerability which affects a few popular ad blockers and could potentially allow for all manner of nastiness to be inflicted.

According to Armin Sebastian, the flaw is present in Adblock, Adblock Plus and uBlock, and pertains to a new filter option introduced by Adblock Plus version 3.2 in July 2018, which was subsequently adopted by the other ad blocking extensions (uBlock is also owned by Adblock, in case you were wondering, and is unrelated to uBlock Origin).

The new filter option in question is for rewriting requests, and is essentially used to remove tracking data and prevent adverts from getting around being blocked. However, Sebastian notes that: “Under certain conditions the $rewrite filter option enables filter list maintainers to inject arbitrary code in web pages.”

What’s rather worrying is that this feature is described as “trivial” to exploit, and could have widespread impact given that the aforementioned ad blockers have in excess of 100 million active users.

Someone exploiting this hole in the filter system could engage in all sorts of malicious activity, such as pilfering your online logins, for example.

The security researcher further observed that the exploit can be leveraged across all major browsers, and with web services that fit certain criteria detailed in his blog post. That includes Google services such as Gmail, Maps, and Google Images.

Sebastian says: “Please note that the vulnerability is not limited to Google services, other web services could be affected as well.”

He has contacted Google regarding the vulnerability, but was told by the company that the flaw was ‘intended behavior’ when it comes to its services – in other words, this is an issue for the makers of the ad blockers to sort out, and nothing to do with Google.

Sebastian believes this is an unfortunate conclusion to reach, and points out that the problem isn’t just about flaws in the ad blocking browser extensions, but also web service vulnerabilities, all of which are chained together to allow the exploit.

Non-trivial pursuit

Adblock Plus, meanwhile, has acknowledged the issue, although the company couches the exploit in very different terms, describing it as “non-trivial” to exploit – in direct opposition to what the security researcher believes – and underlining that it will only work for some websites.

Still, Adblock Plus admits it’s a serious matter, and that “despite the actual risk being very low, we have decided to remove the rewrite option and will accordingly release an updated version of Adblock Plus as soon as technically possible.”

The company adds: “We are doing this as a measure of precaution. There has not been any attempt of abusing the rewrite option and we will do everything we can to ensure this won’t happen.”

While the risk may (or may not) be low, as Adblock Plus claims, the stakes have doubtless got a bit higher now that the exploit is public knowledge.

So, until a new updated version of Adblock Plus (and presumably the other ad blockers affected by the flaw) is released, what can you do in the meantime?

Sebastian advises that users might want to consider switching to uBlock Origin, which doesn’t have the $rewrite filter option, and so is in the clear – at least until the issue has been sorted with the affected ad blocking extensions.

Via ZDNet

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Computing Security
View on National Assembly building in Paris, France, with French and European flags flying.
France rejects controversial encryption backdoor provision
ensure data security for your business
The complete data protection system for your business
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Man uses a laptop in a hotel room
4 ways to avoid misinformation on social media and retain control of your newsfeed
An AI face in profile against a digital background.
Worried about DeepSeek? Well, Google Gemini collects even more of your personal data
Apple
"We will never build a backdoor" – Apple kills its iCloud's end-to-end encryption feature in the UK
Latest in News
Google Chromecast 2
Google is finally rolling out a fix for broken Chromecasts – just as new bugs appear on the Chromecast with Google TV
Garmin Instinct 3 in Neotropic Green
"I'm an idiot": Garmin user reveals how fixing one setting completely changed their training after months of making no progress
The main battle pass characters in Fortnite Lawless, including Midas, Sub Zero and a large wolf-man
You'll finally be able to play Fortnite on Windows 11 Arm-powered laptops as Epic Games partners with Qualcomm
DeepSeek on an iPhone
OpenAI calls on US government to ban DeepSeek, calling it ‘state-subsidized’ and ‘state-controlled’
Apple iPhone 16e REVIEW
Some iPhone 16e owners are reporting Bluetooth audio issues that could be an iOS problem
The TikTok logo appears on a smartphone screen with the United States flag in the background
Oracle could still end up running TikTok