Light

Episode #1040 Quiz

Clickjacking "Whac-A-Mole"
Date: 2025-08-26 | Length: 2.25 hrs | Episode page at twit.tv

About this episode

This episode analyzed a recent DEFCON 33 revelation of DOM-based clickjacking vulnerabilities in browser extensions for password managers like 1Password and Bitwarden, demonstrating how malicious sites trick users into autofilling sensitive data via hidden overlays. Despite patches, complete mitigation remains elusive due to usability-security trade-offs, underscoring inherent risks in browser-based autofill amid complex web interactions.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What legal argument is being used by Axel Springer in Germany's Federal Supreme Court case against Eyeo's Adblock Plus?
Question 2: According to the episode, why is the recent clickjacking zero-day vulnerability affecting browser password managers considered an ongoing "Whac-A-Mole" problem?
Question 3: Why did Bluesky suspend its service in Mississippi as discussed in the episode?
Question 4: What is the core reason the episode gives for the criticality of the recently patched Apple vulnerability CVE-2025-43300?
Question 5: What key security practice does the episode emphasize based on the Docker Desktop escape vulnerability CVE-2025-9074?
Cancel