Sceawere

Vulnerability Detail

CVE-2026-19986UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Adblock for Youtube Improper Authorization

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
4h ago
Vendor
n/a
Product
Adblock for Youtube Extension
Attack Type
Improper Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the function updateDynamicRules of the file contentscript.js of the component Event Listener. This manipulation of the argument yt-anti-adblock-detected causes improper authorization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-08-17T05:17:10.293Z",
  "pubdate": "2026-08-17T05:17:10.293Z",
  "executiveSummary": "An improper authorization vulnerability has been identified in the Adblock for Youtube Extension up to 7.2.1 on Chrome. The vulnerability resides within the Event Listener component, specifically inside the updateDynamicRules function located in contentscript.js. This security flaw stems from insufficient validation and authorization checks surrounding the manipulation of the yt-anti-adblock-detected argument.\nThe impact of this vulnerability allows remote attackers to interact with or manipulate dynamic rule updates improperly. Since an exploit has been publicly disclosed and the vendor has failed to respond to early disclosure attempts, the risk of exploitation in the wild is significantly elevated.\nThe affected system is the Adblock for Youtube Extension running on Google Chrome up to version 7.2.1. Attackers require no prior authentication or elevated privileges to initiate the attack, as the component is exposed remotely through the extension architecture. Successful exploitation could lead to unauthorized modification of extension behavior or security controls related to anti-adblock detection mechanisms.\nOrganizations and end-users utilizing the affected extension face potential integrity issues regarding dynamic rules. Because the vendor has not provided an official patch or response, mitigation is limited to administrative controls or disabling the vulnerable extension.",
  "technicalDetails": "The root cause of the vulnerability is improper authorization handling within the Event Listener component of the Adblock for Youtube Extension. Specifically, the function updateDynamicRules inside contentscript.js fails to properly authorize incoming requests or validate the integrity of the data supplied to the yt-anti-adblock-detected argument.\nThe vulnerable component is the contentscript.js script of the Event Listener component, affecting versions up to 7.2.1 on the Google Chrome browser. The interface exposes functionality that can be triggered remotely, allowing an external actor to interact with the contentscript context without proper session validation or privilege verification.\nThe attack flow begins when a remote entity interacts with the extension's event listener mechanism. By supplying a maliciously crafted or manipulated payload targeting the yt-anti-adblock-detected argument, the attacker bypasses intended authorization boundaries. The updateDynamicRules function processes this unauthorized input, leading to improper execution flow and unauthorized manipulation of the extension's dynamic rule set.\nExploitation requires network exposure via the browser extension's event handling surface, but does not necessitate local access, pre-existing authentication, or high privilege levels. The payload behavior involves forcing the extension to process unauthorized rule modifications, potentially disrupting the intended functionality of the ad-blocking mechanism or interfering with anti-detection logic.\nPost-exploitation impact includes the potential degradation of extension integrity, unauthorized state manipulation regarding anti-adblock detection, and potential secondary impacts on browser DOM or storage depending on how the dynamic rules are subsequently enforced by the extension runtime."
}
CVE-2026-19986: Adblock for Youtube Improper Authorization (MEDIUM Severity, CVSS: 5.4) - Sceawere