Definition · Security Headers
What is Clickjacking?
Clickjacking, sometimes called a UI redress attack, exploits the fact that a browser will happily render another site inside a frame while the user’s session cookies for that site still apply. The attacker builds a page with attractive bait — a video play button, a competition entry, a download link — and positions the victim site in a transparent or precisely offset frame above it. The user aims at the bait and actually clicks a button on the framed application, authenticated as themselves.
Variants extend the same idea. Likejacking targets social media actions. Cursorjacking misrepresents the pointer position. Drag-and-drop attacks use framed content to move data between origins rather than to trigger a click.
What an attacker can achieve
Anything a single authenticated interaction can do: approving a payment or an OAuth consent screen, changing a setting, enabling a permission, deleting content, or granting access. It does not let the attacker read the framed page — the same-origin policy still applies — so clickjacking is about causing state-changing actions blind, not about exfiltrating data. Application endpoints where one click has significant consequences are the ones worth protecting hardest.
Defences
Content-Security-Policy: frame-ancestors— the current, precise control.'none'forbids framing entirely; a list of origins permits only those.- X-Frame-Options — the older header, with
DENYandSAMEORIGIN. Where both are present, modern browsers honourframe-ancestors, so setting both is a compatibility measure rather than a conflict. SameSitecookies —LaxorStrictmeans cookies are not sent with many cross-site framed requests, which blunts the attack even where framing is possible.- Confirmation steps for consequential actions — re-authentication or a typed confirmation defeats a single stolen click.
Legacy JavaScript “frame busting” scripts are not a substitute; they have been bypassed in numerous ways and can be neutralised by the sandbox attribute on the framing iframe.
Checking your own estate
Framing protection is a per-response header, so it is easy for it to be present on the main application and absent on an older subdomain, a marketing site, or an admin panel behind a different server. Auditing across every host, not just the flagship domain, is the part organisations most often get wrong.
Related concepts
See CSP, X-Frame-Options, cross-site scripting, security headers and OWASP Top Ten.