Novel clickjacking attack relies on CSS and SVG
ID: 552ac57c-4b31-5766-b59b-999c6aa93c49
STIX ID: report--552ac57c-4b31-5766-b59b-999c6aa93c49
Feed Name: The Register (Security)
Security researcher Lyra Rebane disclosed a novel SVG/CSS-based clickjacking technique that abuses SVG filters (feBlend, feComposite, etc.) to leak cross-origin pixel data and implement logic gates for complex UI redress attacks; she demonstrated a proof-of-concept that can exfiltrate Google Docs content via framing or HTML injection. The technique bypasses typical frame defenses, affects multiple browsers (including Firefox), earned a Google bug bounty, and remains unmitigated while mitigations such as using frame-ancestors, CSP, or Intersection Observer v2 are suggested.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
