logo

Meet clickjacking's slicker cousin, 'gesture jacking,' aka 'cross window forgery'

ID: ae0d33ae-1cf2-5b2e-9932-af4d8b5f8e82

STIX ID: report--ae0d33ae-1cf2-5b2e-9932-af4d8b5f8e82

Feed Name: The Register (Security)

Date Published: 2024-04-03

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

This report outlines a clickjacking variant, 'cross window forgery' (aka gesture jacking), where attackers prompt users to hold a key and then open a new window whose URL fragment focuses a predictable element (e.g., an OAuth 'Authorize' button), causing the held key to trigger unintended actions and potentially enable account takeover. Because browsers treat this focus/fragment behavior as intended, the piece emphasizes developer-side mitigations: avoid or randomize sensitive element IDs, strip URL fragments on load, use force-load-at-top/disable Scroll-to-Text-Fragment where available, enforce CSP frame-ancestors, and disable sensitive controls until windows are properly sized and keys are released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.