We experimentally validated existing injection attacks on mobile browser extensions. With the ability of malicious actors established, an extension was created that contained common JavaScript vulnerabilities that would enable those abilities to be exercised, consequently, underscoring the need for a defense against them.