Web Hack List

Preliminary research

The Click that shouldn't have worked: RCE via clickjacking in Internet Explorer

The Click that shouldn’t have worked: RCE via clickjacking in Internet Explorer

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Internet Explorer's engine still ships as the WebBrowser control inside .NET and VB applications. A file downloaded through http://localhost arrives with no Mark of the Web, so a dropped HTML page runs as a local file and reaches WScript.Shell through ActiveX. Further sections add an NTLM leak, UXSS, XAML and ClickOnce handlers, and clickjacking and drag-and-drop paths to two-click RCE.

Record

Document
The Click that shouldn’t have worked: RCE via clickjacking in Internet Explorer
Researcher
Igor Sak-Sakovskiy and @Psych0tr1a
Published by
PT SWARM
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Igor Sak-Sakovskiy and @Psych0tr1a, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .