The only solution I could come up with for Android/iOS was to run a remote digital ocean firewall to block all ads at the network level, and connect to it with a VPN. Everything else I've tried or implemented on the devices themselves ate up too much resouces or had to be dangerously elevated in privilege (NDK) just to stop the damn ads. A bonus of this method is you can also experiment with filtering known Android bugs before they reach your device if for whatever reason you can't update your system.img
Mobile ads are the worst. They hijack the whole screen, float around make it impossible to view content, are a pain to dismiss, and they hijack scrolling.
They are also highly likely to be a carrier for malware. Good riddance to such rubbish
Then scrubbed traffic is passed to Snort (or use Suricata), with a ruleset to look for attack signatures. You can update rulesets from mailing lists https://lists.emergingthreats.net/mailman/listinfo/emerging-... and make your own by following whoever on Twitter is involved in Android/iOS security like @pof (Pau Oliva). There are specific mobile "emerging threat" rulesets too https://lists.emergingthreats.net/pipermail/emerging-sigs/20...
Now you can install Ublock Origin on your phone browser and most of the work it has to do is already done saving memory and bandwidth. Here you can experiment with custom rulesets for how pages get displayed, whitelist certain objects you may wish to look at and not blindly block. To further go down the rabbit hole you can build your own mobile version of FF on your VM, ripping out all these harmful things: https://sites.google.com/a/chromium.org/dev/Home/chromium-se...
You can also set up a script on the VM to update Android on AWS. If say there's a new web views critical bug, and a patch is released your VM script (Ansible/Chef) can start an AWS instance, get the latest patch(s) and completely build a new system.img automatically. This can all be done with a custom app you write with the backend hosted on your VM, or with Termux or KBOX, and automate/abstract away all the ssh key logins and tasks with a script. Open your app see all available new Android patches, then click "Build" to automate your new system.img with your own signatures.
Of course you don't have to use any of these tools, you could learn about their innards then roll your own software. If you are a javascript developer have the pf firewall dump it into your custom interpreter on the VM, that can look for unusual behaviour and just pass scrubbed js to your browser on the phone.
Maybe I'm missing something obvious. It's been a long day...
javascript:(function(){document.styleSheets[0].addRule(".highlighted_to_remove","background:red !important");var e=function(e){if(e.keyCode==27){i()}};document.addEventListener("keydown",e);var t=function(e){e.stopPropagation();this.classList.add("highlighted_to_remove");return false};var n=function(e){e.stopPropagation();this.classList.remove("highlighted_to_remove");return false};var r=function(e){this.parentNode.removeChild(this);i();e.preventDefault();e.stopPropagation();return false};var i=function(){var i=0;var s=document;while(s=document.body.getElementsByTagName("*").item(i++)){s.removeEventListener("mouseover",t);s.removeEventListener("mouseout",n);s.removeEventListener("click",r);s.classList.remove("highlighted_to_remove")}document.removeEventListener("keydown",e)};var s=0;var o=document;while(o=document.body.getElementsByTagName("*").item(s++)){o.addEventListener("mouseover",t);o.addEventListener("mouseout",n);o.addEventListener("click",r)}})() javascript:(function(){var e=document.body.style.cursor;document.body.style.cursor="crosshair";var t=document.createElement("div");var n="border:1px solid #3280FF;background-color:rgba(50,128,255,0.5);position:absolute;z-index:999999999999999;display:none;";var%20r="pointer-events:none;";var%20i="transition:width%2060ms,height%2060ms,left%2060ms,top%2060ms;";n+=r+"-webkit-"+r+"-moz-"+r;n+=i+"-webkit-"+i+"-moz-"+i;t.setAttribute("style",n);document.body.appendChild(t);var%20s=null;var%20o=function(e){var%20n=e.target;if(n!==s&&n.parentNode){var%20r=n.getBoundingClientRect();var%20i=document.documentElement;var%20o=document.body;var%20u=i.clientTop||o.clientTop||0;var%20a=i.clientLeft||o.clientLeft||0;var%20f=window.pageYOffset||i.scrollTop||o.scrollTop;var%20l=window.pageXOffset||i.scrollLeft||o.scrollLeft;var%20c=l-a+r.left-1;var%20h=f-u+r.top-1;t.style.display="block";t.style.left=c+"px";t.style.top=h+"px";t.style.width=r.width+"px";t.style.height=r.height+"px";s=n}};var%20u=function(n){document.body.style.cursor=e;if(n.target.parentNode)n.target.parentNode.removeChild(n.target);if(t.parentNode)t.parentNode.removeChild(t);window.removeEventListener("click",u,false);window.removeEventListener("mouseover",o,false);n.stopPropagation();n.preventDefault()};window.addEventListener("mouseover",o,false);window.addEventListener("click",u,false)})();void(0)As for the bookmarklet, smashing stuff. I'm always deleting irritating stuff on pages using the inspector.