Popular Adblock for YouTube extension contains remote code execution (opens in new tab)
Inside "Adblock for YouTube," a trusted Chrome extension with 11M+ installs whose architecture could be weaponized by a single server-side change to steal data and hijack sessions
Read the original article