Wed 1 Oct 2008
Your Browser Could Be Clickjacked
Posted by Syd Tash under Security
No Comments
A new type of vulnerability has emerged, that could affect all major browsers. It is being called clickjacking. In essence, your clicks are being hijacked. The researchers who found it just recently are not releasing much information, while the browser publishers work on a fix.
The exploit appears to work as follows. A button linking to a malicious site, or set to perform an unwanted action, can be made to hover invisibly under your mouse pointer. When you click on something you actually see on the Web page, you are also clicking on that invisible button.
The researchers have contacted Microsoft, Mozilla and Apple, makers of the Internet Explorer, Firefox and Safari browsers respectively. These three account for 98% of all browsers. The companies are working on a fix to this problem.
Flash Player from Adobe also appears to be indirectly affected, and they, too, are working on a patch. Flash is a multimedia content player that most of us have installed on our PCs.
Stay tuned for more details.