Collected research
uBlock, I exfiltrate: exploiting ad blockers with CSS
Bypasses of uBlock Origin's cosmetic-filter validation let a malicious or compromised filter list inject arbitrary CSS into every page. A CSS-only exfiltration method then reads text: custom fonts with unicode-range reveal characters, and first-line used as a width mask plus animation extracts a chosen substring, stealing script contents, attributes and passwords.
Record
- Researcher
- Gareth Heyes
- Published by
- PortSwigger Research
- Date
- Topic
- Other
In the archive
Related sources
- All attack demonstrations
- uBlock Origin bypass report
- uBlock Origin injection report
- CSS keylogger PoC
- Stealing script contents PoC
- Stealing first line on Safari PoC
- Stealing n characters on Firefox PoC
- Stealing characters reversed on Firefox PoC
- Stealing attributes in checkboxes PoC
Tags
This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .