US English (US)
FR French
DE German
ES Spanish
IT Italian
NL Dutch
JP Japanese

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • Contact Us
English (US)
US English (US)
FR French
DE German
ES Spanish
IT Italian
NL Dutch
JP Japanese
  • Home
  • Password Boss Knowledgebase
  • Using Password Boss
  • FAQ

0-Day Clickjacking Protection Overview

Our extension employs multiple independent techniques to safeguard users against clickjacking attacks. These measures are designed to ensure that form fields are both secure and accurately represented on the page.

Written by Chris Liles

Updated at August 27th, 2025

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • AutoElevate Knowledgebase
    New to AutoElevate? START HERE General & Troubleshooting Managing Rules Integrations Announcements FAQ Sales & Marketing How to Videos
  • Password Boss Knowledgebase
    Using Password Boss Business Administration Password Boss Partner Documents
  • CyberFOX DNS Filtering
    Getting Started Filtering Policies Company and Location Setup Roaming Clients Reporting and Logging
  • Marketing Toolkit
    MSP Marketing & Education Toolkit
  • Changelogs for Autoelevate and Password Boss
  • Current Status
+ More

Table of Contents

Key Security Features Ongoing Improvements

DOM-based extension clickjacking is a stealthy attack method that exploits the browser's Document Object Model (DOM) to invisibly overlay malicious elements on top of legitimate extension interfaces—particularly those of password managers. By manipulating the DOM, attackers can trick users into unknowingly clicking on hidden UI components, such as autofill buttons or credential fields, thereby exfiltrating sensitive data like usernames, passwords, TOTP codes, and credit card information. These attacks are especially dangerous because they can occur with just a single click on a compromised webpage. This threat is mitigated by Password Boss by using the following techniques:

 

Key Security Features


  1. Input Field Validation
    • The extension continuously monitors and evaluates each input field on the page.
    • It checks several parameters to determine whether a field is truly visible and safe to interact with:
      • Effective Opacity & Visibility: Assesses both the field and its parent elements up to the <body> tag.
      • Field Size: Ignores fields that are too small to be considered visible.
      • Font Size: Enforces a minimum font size of 8px to prevent deceptive rendering.
      • Z-Index & Overlapping: Ensures that other elements do not obscure input fields.
         
  2. Secure Item Display
    • The extension always displays a list of secure items for the top-level page, even if the form is embedded within an iframe.
       
  3. Iframe Restrictions
    • Autologin is disabled for any form located inside an iframe, preventing unauthorized access or manipulation.
       
  4. Safe Popover Rendering
    • Popovers and in-page dialogs are rendered using an embedded page, similar to other extensions.
    • If a malicious site attempts to inject this embedded page, it will only display default content and will not contain the necessary components to trigger form filling.

 

Ongoing Improvements


We are actively working on additional enhancements to strengthen security further by:

  • Detecting opacity changes triggered by CSS animations.
  • Blocking unauthorized iframe embedding of the extension’s interface.

Updated 8/27/2025

clickjacking vulnerability security online threats protective measures deceptive clicks security overview click fraud

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Mobile Upgrade
  • Products
    • Privileged Access Management
    • Password Management
  • Solutions
    • For MSPs
    • For IT Pros
    • By Industry
  • Resources
    • Weekly Demos
    • Events
    • Blog
    • FAQ
  • Company
    • Leadership
    • Culture + Values
    • Careers
    • Awards
    • News & Press
    • Trust Center
    • Distributors
  • Get Pricing
  • Free Trial
  • Request a Demo
  • Support
  • Login
  • Contact
4925 Independence Parkway
Suite 400
Tampa, FL 33634
CALL US (813) 578-8200
  • Link to Facebook
  • Link to Linkedin
  • Link to Twitter
  • Link to Youtube
© 2023 CYBERFOX LLC ALL RIGHTS RESERVED  |  Privacy Policy

Knowledge Base Software powered by Helpjuice

Expand