NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • Contact Us
English (US)
NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish
  • Home
  • Password Boss Knowledgebase
  • Legacy Password Boss
  • Using Password Boss (Legacy)
  • FAQ (Legacy)

0-Day Clickjacking Protection Overview (Legacy)

Our extension employs multiple independent techniques to safeguard users against clickjacking attacks. These measures are designed to ensure that form fields are both secure and accurately represented on the page.

Written by Owen Parry

Updated at April 17th, 2026

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • AutoElevate Knowledgebase
    New to AutoElevate? START HERE AutoElevate Features & Troubleshooting Managing Rules in AutoElevate Integrations for AutoElevate AutoElevate FAQ Selling AutoElevate
  • Password Boss Knowledgebase
    Using Password Boss Administrating Password Boss Legacy Password Boss
  • CyberFOX DNS Filtering
    Getting Started with DNS Filtering DNS Filtering Concepts Network Requirements for DNS Filtering DNS Filtering Company and Location Setup Managing your DNS Filtering Policies Using Roaming Clients for DNS Filtering DNS Filtering Reports & Logs DNS Filtering Troubleshooting
  • Marketing Toolkit
    MSP Marketing & Education Toolkit CyberFOX Brand Guidelines
  • Changelogs for Autoelevate and Password Boss
  • CyberFOX Product Roadmap
  • Current Status
+ More

Table of Contents

Key Security Features Ongoing Improvements

DOM-based extension clickjacking is a stealthy attack method that exploits the browser's Document Object Model (DOM) to invisibly overlay malicious elements on top of legitimate extension interfaces—particularly those of password managers. By manipulating the DOM, attackers can trick users into unknowingly clicking on hidden UI components, such as autofill buttons or credential fields, thereby exfiltrating sensitive data like usernames, passwords, TOTP codes, and credit card information. These attacks are especially dangerous because they can occur with just a single click on a compromised webpage. This threat is mitigated by Password Boss by using the following techniques:

 

Key Security Features


  1. Input Field Validation
    • The extension continuously monitors and evaluates each input field on the page.
    • It checks several parameters to determine whether a field is truly visible and safe to interact with:
      • Effective Opacity & Visibility: Assesses both the field and its parent elements up to the <body> tag.
      • Field Size: Ignores fields that are too small to be considered visible.
      • Font Size: Enforces a minimum font size of 8px to prevent deceptive rendering.
      • Z-Index & Overlapping: Ensures that other elements do not obscure input fields.
         
  2. Secure Item Display
    • The extension always displays a list of secure items for the top-level page, even if the form is embedded within an iframe.
       
  3. Iframe Restrictions
    • Autologin is disabled for any form located inside an iframe, preventing unauthorized access or manipulation.
       
  4. Safe Popover Rendering
    • Popovers and in-page dialogs are rendered using an embedded page, similar to other extensions.
    • If a malicious site attempts to inject this embedded page, it will only display default content and will not contain the necessary components to trigger form filling.

 

Ongoing Improvements


We are actively working on additional enhancements to strengthen security further by:

  • Detecting opacity changes triggered by CSS animations.
  • Blocking unauthorized iframe embedding of the extension’s interface.

Updated 8/27/2025

zero-day clickjacking

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Security policy recommendations
  • Application Whitelisting or Exclusions
Request a Demo
  • Get Pricing
  • Start Trial
  • Contact
  • Support Center
  • Login
Solutions
AutoElevate
  • AutoElevate Overview
  • Remove Admin Privilege
  • Just-in-Time Admin
  • Blocker
Password Manager
  • Password Manager Overview
  • Features
DNS Filtering
  • DNS Filtering Overview
MSPs
IT Departments
  • Overview
  • State and Local Government
  • K-12 Education
  • Manufacturing
  • Higher Education
Resources
  • Resource Center
  • Group Demos
  • Events
  • The Simple 7™
Company
  • About
  • Leadership
  • Culture & Values
  • News & Press
  • Awards
  • Partnerships
  • Referral Program
  • Trust Center
CyberFox Logo

CALL US (813) 578-8200

© 2025 CYBERFOX LLC ALL RIGHTS RESERVED | Privacy Policy | Terms of Service | Sitemap


Knowledge Base Software powered by Helpjuice

Expand