DEF CON 33 - Browser Extension Clickjacking: One Click and Your Credit Card Is Stolen  - Marek Tóth

DEF CON 33 - Browser Extension Clickjacking: One Click and Your Credit Card Is Stolen - Marek Tóth

Source: YouTube · DEFCONConference · published Feb 18, 2026 · 50:11

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Clickjacking is not dead; this presentation demonstrates how browser extensions, specifically password managers, can be exploited via iframe and DOM manipulation to steal credentials and personal data with minimal user interaction 0:00-0:42 11:36-12:03.

Key Takeaways:
• Iframe-based clickjacking exploits misconfigurations in the extension manifest (specifically web_accessible_resources) to load the password manager interface on a malicious domain, resulting in unauthorized data sharing after a few clicks 11:36-12:03.
• DOM-based attacks manipulate the visibility or layering of password manager interfaces, causing users to inadvertently click autofill menus while accepting cookie banners or captchas 14:48-15:46.
• The researcher tested nine popular password managers and found that the vast majority were vulnerable to stealing login credentials, 2FA codes, and credit card data through this technique 31:14-31:26.
• Because password managers autofill across subdomains by default, any Cross-Site Scripting (XSS) vulnerability on a trusted site can trigger these attacks to compromise user credentials 35:36-36:11.
• Four out of seven tested FIDO2 certified passkey solutions were vulnerable to hijacking due to improper session binding, allowing attackers to gain persistent access with a single click 41:32-41:45.

Users can mitigate these risks by disabling manual autofill or restricting extension site access, while developers should implement CSS and DOM protections like mutation observers to detect UI manipulation.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello and welcome to my talk. Uh my my my topic is about browser extension click checking and one click and your credit card is stolen. This is me. Uh I have about 7 years experience in cyber security. Uh during a day I I do penetration tester but in my free time I do security research. This is a reason why I am here as independent security researcher and I am from Czech Republic and my focus in web application security. As you probably know that uh clickjing vulnerability is out of scope on many back boundary back bounty programs and if you if you if it's accepted then it doesn't mean if if it it is has some severity or give you some some rewards and the reason is that the clickjing vulnerability The glitching vulnerability is in these days is very very protected and can be and user uh it…