Back to Blog

What Is Clickjacking and How Websites Use It to Trick You

PB

Patrick Bushe

September 6, 2024 · 5 min read

Clickjacking tricks you into clicking something you can't see. A malicious page loads a real website in an invisible layer on top of its own content. You think you're clicking "Play" or "Claim prize," but your click lands on a hidden button on the real site, such as "Like," "Follow," "Allow" or "Delete account."

How it works

  1. The attacker's page loads the target site inside a frame (an iframe).
  2. The frame is made fully transparent and positioned so a sensitive button sits exactly over something tempting on the attacker's page.
  3. You click the visible decoy; the browser sends the click to the hidden site, where you're already signed in.

Because you're signed in, the action happens with your account.

Common variations

  • Likejacking: tricking people into liking or sharing social media posts.
  • Permission tricks: getting clicks on browser prompts for camera, microphone or notifications.
  • Cursorjacking: showing a fake cursor offset from the real one.
  • Multi-step tricks: "double-click to continue" games that line up two hidden clicks.
  • Extension clickjacking: at the DEF CON security conference in 2025, a researcher showed that autofill menus from several password manager extensions could be hidden and clicked this way, leaking saved details. Several vendors released fixes.

How websites block it

  • X-Frame-Options: a header that tells browsers not to show the site inside frames on other sites.
  • Content Security Policy frame-ancestors: the modern, more flexible version of the same control.
  • SameSite cookies: limit when sign-in cookies are sent from other sites, so framed pages may load signed out.
  • Confirmation steps for important actions, such as re-entering a password before deleting an account.

Most major sites now use these protections, which is why classic clickjacking is less common than it was.

How to protect yourself

  • Be wary of pages that ask for odd clicks: "click here five times," "double-click to verify," or a prize that needs a click to claim.
  • Keep your browser and extensions updated; fixes for these tricks arrive through updates.
  • Set password manager autofill to require a click on the extension itself rather than filling from in-page menus, if your manager offers it.
  • Deny permission prompts you didn't expect, and review site permissions in Chrome's settings.
  • Sign out of important accounts on shared computers.

See invisible iframes and social engineering.

Related browser tricks

Pages that get a click can also try to read or change your clipboard. Clipboard Guard blocks websites from reading your clipboard. It doesn't stop clickjacking itself, so the habits above still matter.

More Tools by Patrick Bushe

Free Chrome extensions to boost your productivity and privacy