I'd wager more on XSS with a questionable ad network. http://en.wikipedia.org/wiki/Cross-site_scripting