Continuing the Chrome extension hacking (see
part 1 and
2), this time I'd like to draw you attention to the oh-so-popular
AdBlock extension. It has
over a million users, is being actively maintained and is a piece of a great software (heck, even I use it!). However - due to how Chrome extensions work in general it is still
relatively easy to bypass it and display some ads. Let me describe two distinct vulnerabilities I've discovered. They are both exploitable in the newest 2.5.22 version.
tl;dr: Chrome AdBlock 2.5.22 bypasses, demo
here and
here, but I'd advise you to read on.