Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-222 — iFrame Overlay
CAPEC-222

iFrame Overlay

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Medium. In an iFrame overlay attack the victim is tricked into unknowingly initiating some action in one system while interacting with the UI from seemingly completely different system.

Mitigation

Configuration: Disable iFrames in the Web browser. | Operation: When maintaining an authenticated session with a privileged target system, do not use the same browser to navigate to unfamiliar sites to perform other activities. Finish working with the target system and logout first before proceeding to other tasks. | Operation: If using the Firefox browser, use the NoScript plug-in that will help forbid iFrames.

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.