the last time I looked at the Flashblock code for Firefox there was a way to still exploit a flash vuln by slowing the page load down or intercepting DOMContentInserted
Chrome is definitely vulnerable. They are a few versions away from making the blocking API non-experimental.
Using an extension to block may be vulnerable but the builtin click to activate is different. No API involved, I can go to youtube with click-to-activate turned on and it doesn't even spin up a plugin process until I click.
Chrome is definitely vulnerable. They are a few versions away from making the blocking API non-experimental.