Failure to imagine an incentive doesn't mean there isn't one. You can't rely on this type of thinking to reason about security. The thing you would have never thought of is what gets you.
For example, an ad provider itself can be hacked by a malicious party, so the "pay money for" part no longer applies.
Or an attack by a state actor or other large entity, where paying for a coordinated disruption of some region or company makes financial or military sense.
Those are just two things that came to my mind, and are likely a fraction of plausible incentives someone might have now or in the future. People are creative and unpredictable. Weird shit happens. Fact is stranger than fiction...
Instead, just ask: should visiting a website ever have the power to freeze your computer without your consent? If you think the answer is no, this is a security bug and it should be fixed.
That’s why I said I’m sure it does exist but based on it only freezing the computer until you reboot it that’s not useful for hackers doing it to make money and doesn’t seem that useful for disruption unless of course you do hack a bigger ad network then I could see it legitimately being disruptive rather than a slight nuisance. It definitely should be fixed though, it’s crazy it’s gone so long with no fix
For example, an ad provider itself can be hacked by a malicious party, so the "pay money for" part no longer applies.
Or an attack by a state actor or other large entity, where paying for a coordinated disruption of some region or company makes financial or military sense.
Those are just two things that came to my mind, and are likely a fraction of plausible incentives someone might have now or in the future. People are creative and unpredictable. Weird shit happens. Fact is stranger than fiction...
Instead, just ask: should visiting a website ever have the power to freeze your computer without your consent? If you think the answer is no, this is a security bug and it should be fixed.