logo

New DoubleClickjacking attack exploits double-clicks to hijack accounts

ID: ceee830c-a51e-5cfd-844e-af1a794da7e1

STIX ID: report--ceee830c-a51e-5cfd-844e-af1a794da7e1

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2025-01-02

Date Updated: 2026-03-27

Author: Lawrence Abrams

...
...

DoubleClickjacking is a newly described UI-redressing technique that abuses the timing of double-clicks and rapid overlay/window switching to cause a victim's second click to land on an exposed control of a legitimate site (e.g., authorizing OAuth apps, accepting MFA prompts, approving web3 transactions). The researcher provided proof-of-concepts against major services, noted the technique bypasses common clickjacking protections, and proposed mitigations (gesture-gated sensitive controls and a potential HTTP header to limit rapid context switching).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.