CWE-1021— Improper Restriction of Rendered UI Layers or Frames (Clickjacking)
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.— MITRE CWE catalog
424 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1021page 2 of 9
- CVE-2021-0438HIGHCVSS 7.8EG 7.82021-04-13
In several functions of InputDispatcher.cpp, WindowManagerService.java, and related files, there is a possible tapjacking attack due to an incorrect FLAG_OBSCURED value. This could lead to local escalation of privilege with no additional e…
- CVE-2021-0386HIGHCVSS 7.8EG 7.82021-03-10
In onCreate of UsbConfirmActivity, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.…
- CVE-2021-0391HIGHCVSS 7.8EG 7.82021-03-10
In onCreate() of ChooseTypeAndAccountActivity.java, there is a possible way to learn the existence of an account, without permissions, due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution…
- CVE-2021-0305HIGHCVSS 7.8EG 7.82021-02-10
In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for ex…
- CVE-2021-0302HIGHCVSS 7.8EG 7.82021-02-10
In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for ex…
- CVE-2020-27059HIGHCVSS 7.8EG 7.82021-01-11
In onAuthenticated of AuthenticationClient.java, there is a possible tapjacking attack when requesting the user's fingerprint due to an overlaid window. This could lead to local escalation of privilege with no additional execution privileg…
- CVE-2020-0366HIGHCVSS 7.8EG 7.82020-09-17
In PackageInstaller, there is a possible permissions bypass due to a tapjacking vulnerability. This could lead to local escalation of privilege using an app set as the default Assist app with User execution privileges needed. User interact…
- CVE-2020-0387HIGHCVSS 7.8EG 7.82020-09-17
In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escalation of privilege and account hijacking with no additional execution privileges needed. Us…
- CVE-2020-0394HIGHCVSS 7.8EG 7.82020-09-17
In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no additional execution…
- CVE-2020-0051HIGHCVSS 7.8EG 7.82020-03-10
In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack. This could lead to local escalation of privilege in Settings with no additional execution privileges needed. User interaction is needed for exploitation.Produc…
- CVE-2018-9524HIGHCVSS 7.8EG 7.82018-11-14
In functionality implemented in System UI, there are insufficient protections implemented around overlay windows. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed f…
- CVE-2018-9458HIGHCVSS 7.8EG 7.82018-11-06
In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interception of keypresses due to focus being on the wrong window. This could lead to local escalation of privilege revealing the user's keypress…
- CVE-2024-31324HIGHCVSS 7.3EG 7.82024-07-09
In hide of WindowState.java, there is a possible way to bypass tapjacking/overlay protection by launching the activity in portrait mode first and then rotating it to landscape mode. This could lead to local escalation of privilege with Use…
- CVE-2026-74958HIGHCVSS 7.5EG 7.52026-08-18
Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- CVE-2026-60370HIGHCVSS 7.5EG 7.52026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability a…
- CVE-2026-40957HIGHCVSS 7.5EG 7.52026-07-15
o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator.
- CVE-2025-14812HIGHCVSS 7.5EG 7.52025-12-19
ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being shown after an iframe-triggered URI-scheme navigation, increasing spoofing risk.
- CVE-2024-2613HIGHCVSS 7.5EG 7.52024-03-19
Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerability affects Firefox < 124.
- CVE-2022-36319HIGHCVSS 7.5EG 7.52022-12-22
When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, a…
- CVE-2018-7491HIGHCVSS 7.5EG 7.52018-02-26
In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might lead to state-changing impact in the context of a user or an admin, because the generateHtaccess function in classes/Tools.php sets neither X-Fr…
- CVE-2026-18534HIGHCVSS 7.4EG 7.42026-08-18
ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.
- CVE-2026-12348HIGHCVSS 7.4EG 7.42026-06-17
Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain in the address bar while rendering attacker-controlled content, enabling phishing.
- CVE-2025-15032HIGHCVSS 7.4EG 7.42026-01-16
Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof a trusted domain in the window title and mislead users about the current site.
- CVE-2025-14809HIGHCVSS 7.4EG 7.42025-12-19
ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.
- CVE-2025-13132HIGHCVSS 7.4EG 7.42025-11-21
This vulnerability allowed a site to enter fullscreen, after a user click, without a full-screen notification (toast) appearing. Without this notification, users could potentially be misled about what site they were on if a malicious site …
- CVE-2022-22807HIGHCVSS 7.4EG 7.42022-02-09
A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use the web interface rendered within iframe…
- CVE-2021-1403HIGHCVSS 7.4EG 7.42021-03-24
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site WebSocket hijacking (CSWSH) attack and cause a denial of service (DoS) condition on an affected device. …
- CVE-2026-2378HIGHCVSS 6.5EG 7.42026-03-20
ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.
- CVE-2026-28656HIGHCVSS 7.3EG 7.32026-09-08
In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ne…
- CVE-2026-37470HIGHCVSS 7.3EG 7.32026-05-26
An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTP response security headers components
- CVE-2025-48639HIGHCVSS 7.3EG 7.32025-12-08
In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User …
- CVE-2025-22419HIGHCVSS 7.3EG 7.32025-09-02
In multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. U…
- CVE-2025-22417HIGHCVSS 7.3EG 7.32025-09-02
In finishTransition of Transition.java, there is a possible way to bypass touch filtering restrictions due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
- CVE-2022-20501HIGHCVSS 7.3EG 7.32022-12-13
In onCreate of EnableAccountPreferenceActivity.java, there is a possible way to mislead the user into enabling a malicious phone account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User executi…
- CVE-2022-20442HIGHCVSS 7.3EG 7.32022-12-13
In onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a separate app with API level < 23 due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution pri…
- CVE-2021-39691HIGHCVSS 7.3EG 7.32022-06-15
In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed…
- CVE-2021-39796HIGHCVSS 7.3EG 7.32022-04-12
In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privile…
- CVE-2021-1016HIGHCVSS 7.3EG 7.32021-12-15
In onCreate of UsbPermissionActivity.java, there is a possible way to grant an app access to USB without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privile…
- CVE-2021-0954HIGHCVSS 7.3EG 7.32021-12-15
In ResolverActivity, there is a possible user interaction bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Produc…
- CVE-2021-0583HIGHCVSS 7.3EG 7.32021-10-11
In onCreate of BluetoothPairingDialog, there is a possible way to enable Bluetooth without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User intera…
- CVE-2021-0598HIGHCVSS 7.3EG 7.32021-10-06
In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devices due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interac…
- CVE-2021-0538HIGHCVSS 7.3EG 7.32021-06-22
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User inter…
- CVE-2021-0537HIGHCVSS 7.3EG 7.32021-06-22
In onCreate of WiFiInstaller.java, there is a possible way to install a malicious Hotspot 2.0 configuration due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User in…
- CVE-2021-0523HIGHCVSS 7.3EG 7.32021-06-21
In onCreate of WifiScanModeActivity.java, there is a possible way to enable Wi-Fi scanning without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. Use…
- CVE-2021-0506HIGHCVSS 7.3EG 7.32021-06-21
In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is nee…
- CVE-2021-0446HIGHCVSS 7.3EG 7.32021-04-13
In ImportVCardActivity, there is a possible way to bypass user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.…
- CVE-2021-0333HIGHCVSS 7.3EG 7.32021-02-10
In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that obscures the phonebook permissions dialog when a Bluetooth device is connecting. This could lead to local escalation o…
- CVE-2021-0331HIGHCVSS 7.3EG 7.32021-02-10
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure default value. This could lead to local escalation of privilege and notification access with User execution privileges needed…
- CVE-2021-0314HIGHCVSS 7.3EG 7.32021-02-10
In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User …
- CVE-2021-0315HIGHCVSS 7.3EG 7.32021-01-11
In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execut…
Map vulnerabilities like CWE-1021 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1021 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →