BOOK THIS SPACE FOR AD
ARTICLE ADHenece notes that the URL does not implement the X-Frame-Options header or the Content Security Policy (CSP) header (Frame-Ancestors).
I I wrote a script that successfully executed the attack.
Saved it as an .html file and opened it in a web browser.
Attack Details: I successfully performed a clickjacking attack using the following URLs:
Target URL: https://gemini.google.com/.
Affected URL: https://gemini.google.com/_/bscframe.
CVE ID: https://nvd.nist.gov/vuln/detail/CVE-2021-35237.