Source |
The Hacker News |
Identifiant |
8632412 |
Date de publication |
2025-01-01 18:54:00 (vue: 2025-01-01 15:08:19) |
Titre |
New "DoubleClickjacking" Exploit Bypasses Clickjacking Protections on Major Websites |
Texte |
Threat hunters have disclosed a new "widespread timing-based vulnerability class" that leverages a double-click sequence to facilitate clickjacking attacks and account takeovers in almost all major websites.
The technique has been codenamed DoubleClickjacking by security researcher Paulos Yibelo.
"Instead of relying on a single click, it takes advantage of a double-click sequence," Yibelo said.
Threat hunters have disclosed a new "widespread timing-based vulnerability class" that leverages a double-click sequence to facilitate clickjacking attacks and account takeovers in almost all major websites.
The technique has been codenamed DoubleClickjacking by security researcher Paulos Yibelo.
"Instead of relying on a single click, it takes advantage of a double-click sequence," Yibelo said. |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
account advantage all almost attacks based been bypasses class click clickjacking codenamed disclosed double doubleclickjacking exploit facilitate has have hunters instead leverages major new paulos protections relying researcher said security sequence single takeovers takes technique threat timing vulnerability websites widespread yibelo |
Tags |
Vulnerability
Threat
|
Stories |
|
Move |
|