logo

New SVG Clickjacking Attack Let Attackers Create Interactive Clickjacking Attacks

ID: 233a6517-f039-544d-9772-80ca16ab1277

STIX ID: report--233a6517-f039-544d-9772-80ca16ab1277

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**SVG clickjacking**: A researcher (Lyra) disclosed a novel technique that repurposes SVG filters (feDisplacementMap, feColorMatrix, feComposite) to build logic gates in the browser rendering pipeline, enabling cross-origin pixel reading, responsive overlays, and data exfiltration (demonstrated via QR-encoded URLs); a proof-of-concept against Google Docs earned a $3,133.70 bug bounty.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.