Clickjacking hides the real control beneath the click
Clickjacking puts something you would never click underneath something you would.
The page you can see is a decoy. Layered invisibly over it is a real control from a real site you are already logged into, positioned so the button you meant to press sits exactly on top of it. You click what you intended; the click lands somewhere else. You have authorised something without ever seeing it, and from the other site's point of view you did it deliberately, which is the part that makes it hard to argue with afterwards.
More on Browser security
- Same-origin policy limits which pages can read each otherSame room, different desks
- CORS relaxes browser reading rules, not authenticationA propped hatch, not a checkpoint
- SameSite cookies reduce some cross-site request risksSome journeys, not every journey
- Browser extensions inherit powerful visibilityEverything passes under it
- Local storage is convenient, not a secure vaultOpen shelves by the door
- Content Security Policy constrains script sourcesOnly from the addresses you wrote down
