CVE-2026-19986
Adblock for Youtube Extension Event Listener contentscript.js updateDynamicRules improper authorization
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the function updateDynamicRules of the file contentscript.js of the component Event Listener. This manipulation of the argument yt-anti-adblock-detected causes improper authorization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
| CWE | CWE-285 CWE-266 |
| Vendor | n/a |
| Product | adblock for youtube extension |
| Published | Aug 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a adblock for youtube extension
Be the first to know when new medium vulnerabilities affecting n/a adblock for youtube extension are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / Adblock for Youtube Extension
7.2.0 7.2.1
References
vuldb.com: https://vuldb.com/vuln/391190 vuldb.com: https://vuldb.com/vuln/391190/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19986 vuldb.com: https://vuldb.com/submit/873935 github.com: https://github.com/xryj920/chrome_extensions/blob/main/AdBlock%20Ltd.%20Adblock%20for%20Youtube%207.2.1%20allows%20persistent%20disabling%20of%20ad%20blocking%20through%20an%20unauthenticated%20DOM%20event
Credits
๐ DRXYJ (VulDB User) VulDB CNA Team