ui-redress-attack

1 article
sort: new top best
clear filter
0 5/10

WhatsApp's web client was vulnerable to clickjacking attacks due to missing X-Frame-Options header and iframe busting techniques, allowing attackers to trick users into sending messages, creating groups, or making calls on their behalf. The vulnerability was reported to Facebook in January 2015 and subsequently fixed with an X-Frame-Options: Deny header.

WhatsApp Facebook Telegram Mohamed A. Baset Seekurity Brian Acton Jan Koum
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details