Researcher: Adblock, Adblock Plus, uBlock browser extensions could have let providers of filtering lists run arbitrary code in sites; uBlock Origin not affected
Third-party providers of content filter rules could stiff netizens — A feature introduced last year in Adblock Plus and a few …
Context & Ripple Effects
Ad-blocking extensions sit at a chokepoint: they execute whatever their filter lists tell them on every page a user visits. The ecosystem has been here before — the PageFair hack pushed malware to visitors of 500+ sites through anti-ad-blocking infrastructure, and AdGuard later warned that popular blockers depend so heavily on community-run EasyList that throttling it by YuZu left many unable to update at all.
First-order effects
- Users running Adblock, Adblock Plus or uBlock are exposed to whoever supplies their filtering rules, since those providers could run arbitrary code inside sites; uBlock Origin users are not affected, making its architecture the differentiator among otherwise similar tools.
Second-order effects
- Trust migrates toward uBlock Origin, pressuring rivals to rework how they consume third-party filter lists — just as Google's Manifest V3 changes were already splitting blocker capabilities between Chrome and Mozilla in the growing extension disparities.
Third-order effects
- Filter-list maintainers become de facto privileged infrastructure: combined with the EasyList dependency, control over rule distribution is emerging as the real power layer of the ad-block ecosystem, with security posture determining which implementations survive.
The trend: Ad blocking is consolidating around whichever implementation treats its filter supply chain as trusted code execution, with list providers holding access-layer power over hundreds of millions of browsing sessions.