Clickjacking: stolen clicks through an invisible frame

If any site can put your page in a frame, it can make the frame invisible and line a button of yours up under something the visitor wants to click.

Example

Frameable
HTTP/1.1 200 OK
Content-Type: text/html
(no X-Frame-Options, no CSP frame-ancestors)
Protected
Content-Security-Policy: frame-ancestors 'self'
X-Frame-Options: DENY

How it happens

The attacker's page loads yours in a transparent iframe, positioned so that "Delete account", "Confirm payment" or "Allow camera" sits under a harmless-looking button. The visitor is logged in to your site, so the click is real. Any page that changes state with a single click is a target.

How to fix it

Tell the browser who may frame you.

  • Content-Security-Policy: frame-ancestors 'self' (or 'none')
  • X-Frame-Options: DENY or SAMEORIGIN for older browsers
  • Send them as headers on every HTML response
  • Ask for confirmation on destructive actions as a second line

How RepoVerse finds it

  • ModeratePages can be framed by any site

    Another site can load your pages in an invisible frame and trick a logged-in visitor into clicking buttons they cannot see — changing settings, confirming payments.

    website · CWE-1021

Questions

Can I set frame-ancestors in a meta tag?
No. Browsers ignore frame-ancestors in a <meta> CSP, so it has to be an HTTP header.
What if my page is meant to be embedded?
List the sites allowed to embed it in frame-ancestors instead of leaving framing open to everyone.

Related

Updated 2026-10-11