Is AdBlock Ninja – Block Ads, Boost Privacy, and Browse Faster safe?

Medium risk

AdBlock Ninja reads your precise device location and sends it to its own servers during account signup and social login.

When you create an account or sign in with Apple or Google in the extension's popup, AdBlock Ninja requests your precise geolocation and attaches your latitude and longitude to the request sent to its backend at api.adblockninja.com, alongside your login credentials or OAuth token. This happens automatically once location permission is granted and is not required to complete signup, so most users who allow the location prompt won't notice the data was sent. As an ad blocker, the extension has no stated feature that needs your location.

adblockninja.hqv1.0.8Chrome Web Store
45Risk
Who publishes it

Birchwood Group, LLC - 6 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
adblockninja.hq
Declared legal entity
Birchwood Group, LLC

Same operator - 6 listings

Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.

Shared hosts - 3 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

abpindo.blogspot.com
Also called by 5 other listings, including Norton VPN, uBlock, AVG VPN
adblock.sk
Also called by 5 other listings, including Norton VPN, uBlock, AVG VPN
acceptableads.com
Also called by 6 other listings

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI FOUND

AdBlock Ninja attaches your precise GPS location to signup and login requests

Creating an account or signing in with Apple or Google prompts for your device's precise location, then attaches it to the request sent to the vendor's own server.

Code analysis shows this on an ad blocker with no location-based feature.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You fill in the signup form, or choose Sign in with Apple or Google, and submit.

The browser then shows its native location-permission prompt for the extension.

The extension did this

The popup reads your precise GPS coordinates and includes them in the same request as your account details.

This happens whether you are creating a new account or logging into an existing one.

02EvidenceCODE COMPARE
The code that does this

Shared location helper, called from all three account flows

What it actually does
getLocation() (index-CvnlquoJ.js)
async function getLocation(timeoutMs = 3000) {
  return new Promise((resolve) => {
    if (!navigator.geolocation) return resolve(null);
    const timeoutId = setTimeout(() => resolve(null), timeoutMs);
    navigator.geolocation.getCurrentPosition(
      (position) => {
        clearTimeout(timeoutId);
        resolve({ lat: position.coords.latitude, lng: position.coords.longitude });
      },
      () => { clearTimeout(timeoutId); resolve(null); },
      { enableHighAccuracy: true, timeout: timeoutMs }
    );
  });
}
// Called identically from registration, Apple login and Google login before
// each is POSTed to api.adblockninja.com.
Registration submit()
async function submit() {
  await schema.validate(form);
  const location = await getLocation();
  if (location) form.location = JSON.stringify(location);
  await axiosRequest.post('/users/register', form);
}
Apple sign-in sendTokenToServer()
async function sendTokenToServer(idToken) {
  const location = await getLocation();
  const payload = { id_token: idToken };
  if (location) payload.location = JSON.stringify(location);
  await axiosRequest.post('/auth/apple', payload);
}
Google sign-in sendTokenToServer()
async function sendTokenToServer(idToken) {
  const location = await getLocation();
  const payload = { id_token: idToken };
  if (location) payload.location = JSON.stringify(location);
  await axiosRequest.post('/auth/google', payload);
}
03EvidenceFIELD TABLE
What the request body contains beyond the location field
FieldValueWhy it matters
Your GPS coordinates
{"lat":40.7306,"lng":-73.9352}Precise latitude and longitude from the browser's location API, accurate to a few meters when granted.
Account details
name=Jane Doe, email=jane.doe@gmail.comYour name, email and password, sent in the same request on the registration path.
OAuth identity token
id_token=eyJhbGciOiJSUzI1NiIsImtpZCI6...The Apple or Google ID token proving who you are, sent alongside the coordinates on the login paths.
04EvidenceTHIRD PARTY LIST
Where the location goes
  • api.adblockninja.com

    The vendor's own account and auth backend. Receives the location field on /users/register, /auth/apple and /auth/google, not a filter-list or ad-serving endpoint.

05EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

What it can do

Permissions this extension asks for, as declared in version 1.0.8. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Store data in your browser

    storage

  • Sign you in with your Google account

    identity

  • Watch every request your browser makes

    webRequest

  • Watch, block and rewrite every request your browser makes

    webRequestBlocking

  • See which of your requests its blocking rules matched

    declarativeNetRequestFeedback

  • Run its own code inside the pages you visit

    scripting

  • See the address and title of every tab you have open

    tabs

  • See every page you navigate to, as you navigate to it

    webNavigation

  • Store an unlimited amount of data in your browser

    unlimitedStorage

  • Read your physical location

    geolocation

  • Block and redirect the requests your browser makes

    declarativeNetRequest

  • Show you desktop notifications

    notifications

webRequestAuthProviderdeclarativeNetRequestWithHostAccess

Where it sends data

Destinations our analysis observed AdBlock Ninja – Block Ads, Boost Privacy, and Browse Faster contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • api.adblockninja.com

    AdBlock Ninja – Block Ads, Boost Privacy, and Browse Faster sends data to api.adblockninja.com. No other extension we have analysed sends data here.

Updated 30 September 2026ofkpehjaciomdhgjmmcmiacobgoncccn