Just a little FYI: Filtering doodad in Adblock Plus opens door to third-party malware injection

Just a little FYI: Filtering doodad in Adblock Plus opens door to third-party malware injection

5 years ago
Anonymous $9jpehmcKty

https://www.theregister.co.uk/2019/04/15/adblock_plus_hole/

A feature introduced last year in Adblock Plus and a few other related content blocking browser extensions allows providers of filtering lists, under certain conditions, to execute arbitrary code on web pages.

Adblock Plus v3.2 for Chrome, Firefox and Opera, released in July 2018, includes support for the $rewrite filter option, which can alter filter rules governing whether or not content gets blocked. The rationale for doing so is that there may be times when it's better to redirect a web request rather than blocking it.