A chrome adblocker extension with more than 10 million installs, "Adblock for youtube", was found was found to have code that could inject arbitrary(possibly malicious) JavaScript, the programming language used by websites, into any website. Usually, extension JavaScript runs in isolated environments, but this extension was found to directly inject JavaScript code into the website code, bypassing restrictions and allowing access to sensitive data such as credit card numbers and passwords. While it is important to note that the issue is dormant and no active exploitation has been detected, the developer requires only a switch on the server side to enable it—no update needs to be manually done in the Chrome Web Store, so it can be done without the user ever knowing.