Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Browser Extension Clickjacking - One Click and Your Credit Card Is Stolen

DEFCONConference via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore a groundbreaking cybersecurity research presentation that unveils a novel clickjacking technique specifically targeting browser extensions. Learn how malicious actors can exploit fake intrusive web elements like cookie consent banners and newsletter modals to trick users into compromising their sensitive data stored in popular browser extensions. Discover the methodology behind testing this attack vector against the 11 most widely used password managers, revealing multiple zero-day vulnerabilities that could potentially affect tens of millions of users worldwide. Understand how a single user click can lead to the theft of critical information including credit card details, personal data, login credentials, and TOTP codes, with some scenarios enabling the exploitation of passkey authentication systems. Gain insights into the broader implications of this technique beyond password managers, as it can be applied to various types of browser extensions including ad blockers and cryptocurrency wallets. Examine the technical details of how attackers can manipulate user interface elements to create convincing fake interactions that bypass extension security measures. Review practical mitigation strategies and security recommendations that extension developers can implement to protect their applications and users from this type of sophisticated attack vector.

Syllabus

DEF CON 33 - Browser Extension Clickjacking: One Click and Your Credit Card Is Stolen - Marek Tóth

Taught by

DEFCONConference

Reviews

Start your review of Browser Extension Clickjacking - One Click and Your Credit Card Is Stolen

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.