What Is Clickjacking and How Websites Use It to Trick You
Patrick Bushe
September 6, 2024 · 5 min read
Clickjacking tricks you into clicking something you can't see. A malicious page loads a real website in an invisible layer on top of its own content. You think you're clicking "Play" or "Claim prize," but your click lands on a hidden button on the real site, such as "Like," "Follow," "Allow" or "Delete account."
How it works
- The attacker's page loads the target site inside a frame (an iframe).
- The frame is made fully transparent and positioned so a sensitive button sits exactly over something tempting on the attacker's page.
- You click the visible decoy; the browser sends the click to the hidden site, where you're already signed in.
Because you're signed in, the action happens with your account.
Common variations
- Likejacking: tricking people into liking or sharing social media posts.
- Permission tricks: getting clicks on browser prompts for camera, microphone or notifications.
- Cursorjacking: showing a fake cursor offset from the real one.
- Multi-step tricks: "double-click to continue" games that line up two hidden clicks.
- Extension clickjacking: at the DEF CON security conference in 2025, a researcher showed that autofill menus from several password manager extensions could be hidden and clicked this way, leaking saved details. Several vendors released fixes.
How websites block it
- X-Frame-Options: a header that tells browsers not to show the site inside frames on other sites.
- Content Security Policy frame-ancestors: the modern, more flexible version of the same control.
- SameSite cookies: limit when sign-in cookies are sent from other sites, so framed pages may load signed out.
- Confirmation steps for important actions, such as re-entering a password before deleting an account.
Most major sites now use these protections, which is why classic clickjacking is less common than it was.
How to protect yourself
- Be wary of pages that ask for odd clicks: "click here five times," "double-click to verify," or a prize that needs a click to claim.
- Keep your browser and extensions updated; fixes for these tricks arrive through updates.
- Set password manager autofill to require a click on the extension itself rather than filling from in-page menus, if your manager offers it.
- Deny permission prompts you didn't expect, and review site permissions in Chrome's settings.
- Sign out of important accounts on shared computers.
See invisible iframes and social engineering.
Related browser tricks
Pages that get a click can also try to read or change your clipboard. Clipboard Guard blocks websites from reading your clipboard. It doesn't stop clickjacking itself, so the habits above still matter.