Обнаружена уязвимость в расширении Adblock for Youtube до версии 7.2.1 в Chrome. Затронутый элемент — это функция updateDynamicRules файла contentscript.js компонента «Прослушиватель событий». Такая манипуляция аргументом yt-anti-adblock-detected приводит к некорректной авторизации.
Атаку можно инициировать удаленно. Эксплойт стал общедоступным и может быть использован для атак. С поставщиком заранее связались по поводу этой информации, но он никак не отреагировал.
Показать оригинальное описание (EN)
A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the function updateDynamicRules of the file contentscript.js of the component Event Listener. This manipulation of the argument yt-anti-adblock-detected causes improper authorization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Характеристики атаки
Последствия
Строка CVSS v4.0