Skip to content

Archive

Clickjacking

2 articles
Cybersecurity 21 Sep 2026 5 min read

CSP frame-ancestors Restricts Page Embedding

CSP frame-ancestors Restricts Page Embedding Clickjacking does not require an attacker to replace the target application’s interface. A hostile page can place the real application inside a transparent or carefully positioned frame, then arrange decoy controls so a user’s click lands on an authenticated action in the framed page. The frame-ancestors directive in Content Security Policy moves the embedding decision to the response being framed. The target declares which ancestors are acceptable. A conforming browser checks the ancestor chain before allowing the protected resource to load in a nested browsing context.

Cybersecurity 11 Sep 2026 8 min read

Block Clickjacking with an Explicit Framing Policy

A sensitive web page can have sound authentication and authorization yet still be exposed through another site’s interface. If an attacker can place that page inside a transparent or disguised frame, a signed-in user may believe they are clicking one control while their click reaches a different control in the framed application. That attack class is clickjacking, also called UI redressing. The browser is doing what both pages request; the security failure is that the sensitive application allowed an untrusted page to become part of its user interface.