Is AdBlock — block ads across the web safe?

Medium risk

AdBlock is medium risk. AdBlock POSTs telemetry to ping.getadblock.com/stats/: persistent user ID, extension ID, version, OS/browser, language, ping count, Acceptable Ads status. The scheduler starts on startup and keeps posting unless opt-out is enabled.

AdBlockv6.46.1Chrome Web Store
45Risk
Who publishes it

ADBLOCK, INC. - no other listings under this identity, 3 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
AdBlock
Declared legal entity
ADBLOCK, INC.
Registered address
12333 Sowden Road, Suite B # 99623, Houston, TX 77080-2059, US
Registered contact
Matt Maier

Shared hosts - 3 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

accounts.adblockplus.org
Also called by 5 other listings, including Adblock Plus, Adblock Plus
help.getadblock.com
Also called by 5 other listings, including AdBlock on YouTube™
vpn.getadblock.com
Also called by 5 other listings, including Adblock Plus, Adblock Plus

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

AdBlock Sends Scheduled Telemetry With User ID

AdBlock POSTs telemetry to ping.getadblock.com/stats/: persistent user ID, extension ID, version, OS/browser, language, ping count, Acceptable Ads status.

The scheduler starts on startup and keeps posting unless opt-out is enabled.

01EvidenceCAUSE EFFECT
What actually happens
You did this

AdBlock starts in the browser and its scheduled telemetry cycle runs.

The extension did this

The extension sends a telemetry ping that links the request to a stored user ID and device context.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://ping.getadblock.com/stats/
Dynamic analysis captured 576 POST requests to this endpoint in about three minutes.
Headers
Content-Typeapplication/json
Body
u=azdafyn013519133
v=6.36.0
o=Mac OS X
bv=146.0.0.0
ov=10_15_7
l=en-GB
pc=279
extid=gighmmpiobklfepjocnamgkkbiglidom
aa=1
03EvidenceFIELD TABLE
Telemetry values observed in the captured request and current source
FieldValueWhy it matters
Your telemetry ID
azdafyn013519133This lets repeated telemetry requests from the same browser profile be linked together over time.
Installed extension
gighmmpiobklfepjocnamgkkbiglidomThis identifies the exact AdBlock extension build sending the telemetry request.
Device and browser context
Mac OS X, Chrome 146.0.0.0, en-GBThis describes the environment where the extension is running.
Telemetry counter
279This shows how many telemetry pings the profile had accumulated in the captured session.
Acceptable Ads status
1This records an extension setting associated with the browser profile.
04EvidenceTEMPORAL PATTERN
When this fires
On an interval

AdBlock schedules telemetry after startup, then reschedules the next ping after each run: one hour after the first install ping, daily for the first week, and weekly after that.

05EvidenceCODE COMPARE
The code that does this

Telemetry ID creation, scheduling, payload assembly, and POST

What it actually does
Telemetry start methoddeobfuscated/abp-background.js
async start() {
    await this.loadUserID();
    // Do 'stuff' when we're first installed...
    // - send a message
    const response = await browser.storage.local.get(this.totalRequestsStorageKey);
    if (!response[this.totalRequestsStorageKey]) {
      if (browser.management && browser.management.getSelf) {
        const info = await browser.management.getSelf();
        if (info) {
          serverLogger.behavior(`new_install_${info.installType}`);
        } else {
          serverLogger.behavior("new_install_unknown");
        }
      } else {
        serverLogger.behavior("new_install_unknown");
      }
    }
    // This will sleep, then ping, then schedule a new ping, then
    // call itself to start the process over again.
    await this.sleepThenPing();
    this.cleanUpLocalStorage();
  }
User ID generator and storage keydeobfuscated/abp-background.js
const userIdStorageKey = "userid";
let userIdPromise = null;
function getUserId() {
    if (userIdPromise) {
        return userIdPromise;
    }
    userIdPromise = (async () => {
        const response = await browser_polyfill.storage.local.get(userIdStorageKey);
        const value = response[userIdStorageKey];
        if (value) {
            return String(value);
        }
        const timeSuffix = (Date.now() % 1e8).toString().padStart(8, "0");
        const alphabet = "abcdefghijklmnopqrstuvwxyz0123456789";
        const result = [];
        for (let i = 0; i < 8; i++) {
            const choice = Math.floor(Math.random() * alphabet.length);
            result.push(alphabet[choice]);
        }
        const newUserId = result.join("") + timeSuffix;
        await browser_polyfill.storage.local.set({ [userIdStorageKey]: newUserId });
        return newUserId;
    })();
    return userIdPromise;
}
Telemetry payload fieldsdeobfuscated/abp-background.js
async getTelemetryData() {
    // AdBlock ping compliance: only the fields required for Monthly Active
    // Client (billing) counting are sent. Diagnostic / UI / feature-flag
    // parameters were removed — the diagnostic data product relied on now
    // flows through the compliant eyeometry events instead.
    let data = {};
    await _alias_prefs__WEBPACK_IMPORTED_MODULE_2__/* .Prefs */ .N.untilLoaded;

    data = {
      u: this.userId,
      v: this.version,
      f: this.flavor,
      o: this.os,
      l: (0,_utilities_background_index__WEBPACK_IMPORTED_MODULE_5__.determineUserLanguage)(),
    };

    if (browser.runtime.id) {
      data.extid = browser.runtime.id;
    }
    const aaStatus = await getAAStatus();
    if (aaStatus) {
      data.aa = aaStatus;
    }

    return data;
  }
Ping send path and opt-out checkdeobfuscated/abp-background.js
sendPingData(pingData) {
    return new Promise(async (resolve, reject) => {
      if (prefs/* Prefs */.N.get("data_collection_opt_out")) {
        resolve();
        return;
      }

      const response = await (0,fetch_util/* default */.A)(prefs/* Prefs */.N.get(this.hostURLPref), pingData)
        // Send any network errors during the ping fetch to a dedicated log server
        // to help us determine why there's been a drop in ping requests
        // See https://gitlab.com/adblockinc/ext/adblock/adblock/-/issues/136
        .catch((error) => {
          background.error("network error during ping");
          background.error("ping server URL: ", prefs/* Prefs */.N.get(this.hostURLPref));
          background.error("error: ", error);
          // retry any ping requests that fail for network errors
          this.retrySendPingData(pingData, resolve, reject);
        });
      if (!response) {
        background.error("no response from ping");
        return;
      }
      if (!response.ok) {
        background.error("Ping server returned error: ", response.statusText);
        this.retrySendPingData(pingData, resolve, reject);
        return;
      }
      background.debug("ping success");
      telemetryNotifier.emit("ping.complete");
      resolve();
    });
  }

  // Tell the server we exist.
  async pingNow() {
    const pingData = await this.getTelemetryData();
    if (!pingData.u) {
      return pingData;
    }
    // attempt to stop users that are pinging us 'a lot'
    // by checking the current ping count,
    // if the ping count is above a theshold,
    // then only ping 'occasionally'.
    // The ping count is read locally rather than from the payload, since it is
    // no longer sent to the server (AdBlock ping compliance).
    const totalPings = await this.getTotalPings();
    if (totalPings > 5000) {
      if (totalPings > 5000 && totalPings < 100000 && totalPings % 5000 !== 0) {
        return pingData;
      }
      if (totalPings >= 100000 && totalPings % 50000 !== 0) {
        return pingData;
      }
    }
    pingData.cmd = "ping";
    void this.sendPingData(pingData);
    return pingData;
  }
POST helper used by telemetrydeobfuscated/abp-background.js
async function postData(url = "", payload = {}) {
  return fetch(url, {
    method: "POST",
    cache: "no-store",
    headers: { "Content-Type": "application/json" },
    body: JSON.stringify(payload),
  });
}
06EvidenceTHIRD PARTY LIST
Telemetry destination
  • ping.getadblock.com

    AdBlock first-party telemetry endpoint receiving the captured POST requests.

  • ping-retry.getadblock.com

    AdBlock first-party retry endpoint used by the shipped code if the primary telemetry request fails.

What it can do

Permissions this extension asks for, as declared in version 6.46.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Schedule its own background tasks

    alarms

  • Add items to the right-click menu

    contextMenus

  • Detect when you step away from your computer

    idle

  • Show you desktop notifications

    notifications

  • Run its own code inside the pages you visit

    scripting

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

  • Store an unlimited amount of data in your browser

    unlimitedStorage

  • See every page you navigate to, as you navigate to it

    webNavigation

  • Watch every request your browser makes

    webRequest

declarativeNetRequestWithHostAccess
Updated 30 September 2026gighmmpiobklfepjocnamgkkbiglidom