Beheben Sie XSS-Angriffe mit Content Security Policy

It depends on what URLs your ads are requesting. You can look at your browser’s console to see them.

See also the relevant section from the OP:

4 „Gefällt mir“