Couldn't Content Security Policy (CSP) [1] be used to mitigate this attack? [1]: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
It actually can't. Instagram does use this protect java-script injection from extensions, but clearly injecting CSS is allowed.
Someone else in this thread suggested that as well.