logo

DoubleClickjacking – New “Double-Click” Attack to Hack Websites & Take over Accounts

ID: efefb51f-b6f8-5fac-bebb-2c57031e1d30

STIX ID: report--efefb51f-b6f8-5fac-bebb-2c57031e1d30

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-01-01

Date Updated: 2026-04-21

Author: Balaji N

...
...

DoubleClickjacking is a newly described web attack that leverages the timing difference between mouse events (mousedown vs. mouseup) and window/opener manipulation to swap in sensitive pages (such as OAuth authorization dialogs) during a two-click sequence, allowing attackers to trick users into authorizing malicious actions; the report details the technique, affected platforms (e.g., Salesforce, Slack, Shopify, browser extensions), demonstrated vulnerabilities, and recommended client-side and browser-level mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.