Tricking Johnny into Granting Web Permissions

We studied the web permission API dialog box in popular mobile and desktop browsers, and found that it typically lacks measures to protect users from unwittingly granting web permission when clicking too fast. We developed a game that exploits this issue, and tricks users into granting webcam permission. We conducted three experiments, each with 40 different participants, on both desktop and mobile browsers. The results indicate that in the absence of a prevention mechanism, we achieve a considerably high success rate in tricking 95 respectively. Interestingly, we also tricked 47 browser where a prevention mechanism exists.


Please sign up or login with your details

Forgot password? Click here to reset