Execution of a clickjacking attack on Gemini (Google’s AI-powered assistant) - which I recently…

1 day ago 10
BOOK THIS SPACE FOR AD
ARTICLE AD

Henece notes that the URL does not implement the X-Frame-Options header or the Content Security Policy (CSP) header (Frame-Ancestors).

I I wrote a script that successfully executed the attack.

Saved it as an .html file and opened it in a web browser.

Attack Details: I successfully performed a clickjacking attack using the following URLs:

Target URL: https://gemini.google.com/.
Affected URL: https://gemini.google.com/_/bscframe.
CVE ID: https://nvd.nist.gov/vuln/detail/CVE-2021-35237.

Read Entire Article