Collected research
Cross Window Forgery: A New Class of Web Attack
A URL fragment matching an element's id focuses that element, and pressing Enter or Space then activates it. The attacker opens target.com/oauth/allow?appId=evil#allow-button in a 1x1 window moved offscreen and asks the victim to hold a key, so the OAuth consent button is clicked in the victim's session; because this is top-level navigation, SameSite cookies and anti-CSRF tokens do not help. A three-window sandwich variant uses a double click instead.
Record
- Published by
- evil.blog
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of evil.blog, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .