{"id":7741,"date":"2026-06-27T11:24:23","date_gmt":"2026-06-27T09:24:23","guid":{"rendered":"https:\/\/viva.racunalniske-novice.com\/priljubljeni-chrome-dodatek-za-blokiranje-oglasov-skriva-nevarno-kodo\/"},"modified":"2026-06-27T11:24:23","modified_gmt":"2026-06-27T09:24:23","slug":"priljubljeni-chrome-dodatek-za-blokiranje-oglasov-skriva-nevarno-kodo","status":"publish","type":"post","link":"https:\/\/viva.racunalniske-novice.com\/fr\/une-extension-populaire-de-blocage-de-publicites-pour-chrome-dissimule-un-code-dangereux\/","title":{"rendered":"Une extension populaire de blocage de publicit\u00e9s pour Chrome dissimule un code dangereux"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Des chercheurs en s\u00e9curit\u00e9 d&#039;Island ont r\u00e9cemment analys\u00e9 en d\u00e9tail l&#039;outil tr\u00e8s populaire \u00ab\u00a0Adblock for YouTube\u00a0\u00bb. Bien que l&#039;extension remplisse parfaitement sa fonction et supprime les publicit\u00e9s de la plateforme et des sites externes, son architecture dissimule une faille de s\u00e9curit\u00e9 importante. Le code permet l&#039;ex\u00e9cution de scripts \u00e0 distance sur n&#039;importe quel site web visit\u00e9.<br><br>Les experts soulignent qu&#039;en pratique, cela signifie la possibilit\u00e9 de lire le contenu de la page, de voler des donn\u00e9es et m\u00eame de g\u00e9rer des comptes personnels et professionnels au nom de l&#039;utilisateur. \u00c0 l&#039;heure actuelle, rien ne prouve que cette vuln\u00e9rabilit\u00e9 ait d\u00e9j\u00e0 \u00e9t\u00e9 exploit\u00e9e. Cependant, la simple existence d&#039;une telle fonction, ainsi que les liens vers d&#039;autres programmes supprim\u00e9s, est suffisamment pr\u00e9occupante. Le Chrome Web Store a r\u00e9cemment retir\u00e9 des extensions associ\u00e9es, telles que \u00ab\u00a0Adblock for Chrome\u00a0\u00bb, \u00ab\u00a0Adblock for You\u00a0\u00bb et \u00ab\u00a0AdBlock Suite\u00a0\u00bb, en raison de la pr\u00e9sence de code malveillant.<br><br>L&#039;extension est disponible sur la boutique en ligne officielle depuis 2014, mais son propri\u00e9taire a chang\u00e9 quatre ans plus tard. Entre 2018 et juin 2024, elle int\u00e9grait le SDK Unistream pour l&#039;\u00ab injection \u00bb de publicit\u00e9s, et depuis f\u00e9vrier 2025, elle inclut des m\u00e9canismes permettant de lancer des scripts externes. L&#039;outil utilise la biblioth\u00e8que open source AdGuard avec de petites fonctions appel\u00e9es \u00ab scriptlets \u00bb. Le probl\u00e8me r\u00e9side dans le fait que le serveur d\u00e9termine lesquels seront ex\u00e9cut\u00e9s. La fonction \u00ab trusted-create-element \u00bb peut cr\u00e9er un \u00e9l\u00e9ment HTML sur une page, et si le serveur lui envoie du code malveillant, celui-ci s&#039;ex\u00e9cute discr\u00e8tement en arri\u00e8re-plan. Les chercheurs avertissent que cette fonctionnalit\u00e9 est actuellement inactive, mais qu&#039;elle peut \u00eatre activ\u00e9e par une simple modification sur le serveur du d\u00e9veloppeur, sans intervention de Google ni mise \u00e0 jour de l&#039;extension elle-m\u00eame.<br><br>Un autre probl\u00e8me r\u00e9side dans le fait que l&#039;extension fonctionne sur tous les sites web, car le contr\u00f4le de s\u00e9curit\u00e9 de l&#039;URL est superficiel. Le code v\u00e9rifie uniquement la pr\u00e9sence de la cha\u00eene \u00ab\u00a0youtube.com\u00a0\u00bb dans l&#039;adresse, ce qui signifie qu&#039;il peut \u00eatre facilement tromp\u00e9 avec des adresses comme bank.example.com\/search?q=youtube.com ou facebook.com\/page?ref=youtube.com.<br><br>Suite \u00e0 la publication du rapport, Mathias Rochus, fondateur d&#039;AdBlock Ltd., a r\u00e9agi. Il a assur\u00e9 que les fonctionnalit\u00e9s n&#039;avaient jamais fait l&#039;objet d&#039;abus et n&#039;en feraient pas l&#039;objet, et a annonc\u00e9 une mise \u00e0 jour urgente. Celle-ci corrigera la validation des URL, qui exigera d\u00e9sormais une correspondance exacte avec l&#039;adresse YouTube, et d\u00e9sactivera l&#039;injection de scripts c\u00f4t\u00e9 serveur. Ce correctif doit \u00eatre approuv\u00e9 par Google avant sa mise en ligne.<\/p>","protected":false},"excerpt":{"rendered":"<p>Varnostni raziskovalci podjetja Island so nedavno pod drobnogled vzeli izjemno priljubljeno orodje &#8220;Adblock for YouTube&#8221;. Kljub temu, da dodatek zanesljivo opravlja svoje delo in odstranjuje oglase s platforme ter zunanjih strani, njegova arhitektura skriva resno varnostno tveganje. Koda namre\u010d omogo\u010da oddaljen prenos in izvajanje poljubnih skript na kateri koli spletni strani, ki jo obi\u0161\u010dete. Strokovnjaki [&hellip;]<\/p>","protected":false},"author":2,"featured_media":0,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[70],"tags":[440,478,482],"class_list":["post-7741","post","type-post","status-publish","format-standard","hentry","category-spletni-brskalniki","tag-chrome-brskalnik","tag-informacijska-varnost","tag-kibernetska-varnost"],"acf":{"subtitle":"","heading":"","summary":"Raziskava raz\u0161iritve \"Adblock for YouTube\" z 10 milijoni prenosov je razkrila spe\u010do funkcijo za oddaljen zagon zlonamerne kode na vseh spletnih straneh. Razvijalci podjetja AdBlock Ltd so po opozorilu \u017ee napovedali izdajo varnostnega popravka.","thumbnail_small":"https:\/\/racunalniske-novice.com\/wp-content\/uploads\/2021\/03\/130321_ChromeRAM-560x315.jpg","thumbnail_large":"https:\/\/racunalniske-novice.com\/wp-content\/uploads\/2021\/03\/130321_ChromeRAM.jpg","thumbnail_caption":"Novi Google Chrome je precej prijaznej\u0161i do sistemskega pomnilnika!","gallery":"","video_gallery":null,"author":"","links":null,"sources":[{"title":"thehackernews","url":"https:\/\/thehackernews.com\/2026\/06\/chrome-ad-blocker-with-10m-installs.html?m=1"}],"skip_language":[]},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.8 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Priljubljeni Chrome dodatek za blokiranje oglasov skriva nevarno kodo - Ra\u010dunalni\u0161ke novice<\/title>\n<meta name=\"description\" content=\"Raziskava raz\u0161iritve &quot;Adblock for YouTube&quot; z 10 milijoni prenosov je razkrila spe\u010do funkcijo za oddaljen zagon zlonamerne kode na vseh spletnih straneh. Razvijalci podjetja AdBlock Ltd so po opozorilu\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/posts\/7741\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Priljubljeni Chrome dodatek za blokiranje oglasov skriva nevarno kodo - Ra\u010dunalni\u0161ke novice\" \/>\n<meta property=\"og:description\" content=\"Varnostni raziskovalci podjetja Island so nedavno pod drobnogled vzeli izjemno priljubljeno orodje &#8220;Adblock for YouTube&#8221;. Kljub temu, da dodatek zanesljivo opravlja svoje delo in odstranjuje oglase s platforme ter zunanjih strani, njegova arhitektura skriva resno varnostno tveganje. Koda namre\u010d omogo\u010da oddaljen prenos in izvajanje poljubnih skript na kateri koli spletni strani, ki jo obi\u0161\u010dete. Strokovnjaki [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/viva.racunalniske-novice.com\/fr\/une-extension-populaire-de-blocage-de-publicites-pour-chrome-dissimule-un-code-dangereux\/\" \/>\n<meta property=\"og:site_name\" content=\"Ra\u010dunalni\u0161ke novice\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-27T09:24:23+00:00\" \/>\n<meta name=\"author\" content=\"sinusiks\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"sinusiks\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/priljubljeni-chrome-dodatek-za-blokiranje-oglasov-skriva-nevarno-kodo\/\",\"url\":\"https:\/\/viva.racunalniske-novice.com\/priljubljeni-chrome-dodatek-za-blokiranje-oglasov-skriva-nevarno-kodo\/\",\"name\":\"Priljubljeni Chrome dodatek za blokiranje oglasov skriva nevarno kodo - Ra\u010dunalni\u0161ke novice\",\"isPartOf\":{\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#website\"},\"datePublished\":\"2026-06-27T09:24:23+00:00\",\"dateModified\":\"2026-06-27T09:24:23+00:00\",\"author\":{\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4\"},\"breadcrumb\":{\"@id\":\"https:\/\/viva.racunalniske-novice.com\/priljubljeni-chrome-dodatek-za-blokiranje-oglasov-skriva-nevarno-kodo\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/viva.racunalniske-novice.com\/priljubljeni-chrome-dodatek-za-blokiranje-oglasov-skriva-nevarno-kodo\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/priljubljeni-chrome-dodatek-za-blokiranje-oglasov-skriva-nevarno-kodo\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/viva.racunalniske-novice.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Priljubljeni Chrome dodatek za blokiranje oglasov skriva nevarno kodo\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#website\",\"url\":\"https:\/\/viva.racunalniske-novice.com\/en\/\",\"name\":\"Ra\u010dunalni\u0161ke novice\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/viva.racunalniske-novice.com\/en\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4\",\"name\":\"sinusiks\",\"sameAs\":[\"https:\/\/ml.racunalniske-novice.com\"],\"url\":\"https:\/\/viva.racunalniske-novice.com\/fr\/author\/sinusiks\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Priljubljeni Chrome dodatek za blokiranje oglasov skriva nevarno kodo - Ra\u010dunalni\u0161ke novice","description":"Raziskava raz\u0161iritve \"Adblock for YouTube\" z 10 milijoni prenosov je razkrila spe\u010do funkcijo za oddaljen zagon zlonamerne kode na vseh spletnih straneh. Razvijalci podjetja AdBlock Ltd so po opozorilu","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/posts\/7741","og_locale":"fr_FR","og_type":"article","og_title":"Priljubljeni Chrome dodatek za blokiranje oglasov skriva nevarno kodo - Ra\u010dunalni\u0161ke novice","og_description":"Varnostni raziskovalci podjetja Island so nedavno pod drobnogled vzeli izjemno priljubljeno orodje &#8220;Adblock for YouTube&#8221;. Kljub temu, da dodatek zanesljivo opravlja svoje delo in odstranjuje oglase s platforme ter zunanjih strani, njegova arhitektura skriva resno varnostno tveganje. Koda namre\u010d omogo\u010da oddaljen prenos in izvajanje poljubnih skript na kateri koli spletni strani, ki jo obi\u0161\u010dete. Strokovnjaki [&hellip;]","og_url":"https:\/\/viva.racunalniske-novice.com\/fr\/une-extension-populaire-de-blocage-de-publicites-pour-chrome-dissimule-un-code-dangereux\/","og_site_name":"Ra\u010dunalni\u0161ke novice","article_published_time":"2026-06-27T09:24:23+00:00","author":"sinusiks","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"sinusiks","Dur\u00e9e de lecture estim\u00e9e":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/viva.racunalniske-novice.com\/priljubljeni-chrome-dodatek-za-blokiranje-oglasov-skriva-nevarno-kodo\/","url":"https:\/\/viva.racunalniske-novice.com\/priljubljeni-chrome-dodatek-za-blokiranje-oglasov-skriva-nevarno-kodo\/","name":"Priljubljeni Chrome dodatek za blokiranje oglasov skriva nevarno kodo - Ra\u010dunalni\u0161ke novice","isPartOf":{"@id":"https:\/\/viva.racunalniske-novice.com\/en\/#website"},"datePublished":"2026-06-27T09:24:23+00:00","dateModified":"2026-06-27T09:24:23+00:00","author":{"@id":"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4"},"breadcrumb":{"@id":"https:\/\/viva.racunalniske-novice.com\/priljubljeni-chrome-dodatek-za-blokiranje-oglasov-skriva-nevarno-kodo\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/viva.racunalniske-novice.com\/priljubljeni-chrome-dodatek-za-blokiranje-oglasov-skriva-nevarno-kodo\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/viva.racunalniske-novice.com\/priljubljeni-chrome-dodatek-za-blokiranje-oglasov-skriva-nevarno-kodo\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/viva.racunalniske-novice.com\/en\/"},{"@type":"ListItem","position":2,"name":"Priljubljeni Chrome dodatek za blokiranje oglasov skriva nevarno kodo"}]},{"@type":"WebSite","@id":"https:\/\/viva.racunalniske-novice.com\/en\/#website","url":"https:\/\/viva.racunalniske-novice.com\/en\/","name":"Ra\u010dunalni\u0161ke novice","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/viva.racunalniske-novice.com\/en\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-FR"},{"@type":"Person","@id":"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4","name":"sinusiks","sameAs":["https:\/\/ml.racunalniske-novice.com"],"url":"https:\/\/viva.racunalniske-novice.com\/fr\/author\/sinusiks\/"}]}},"_links":{"self":[{"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/posts\/7741","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/comments?post=7741"}],"version-history":[{"count":0,"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/posts\/7741\/revisions"}],"wp:attachment":[{"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/media?parent=7741"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/categories?post=7741"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/tags?post=7741"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}