Comment on A clickjacking vulnerability in WhatsApp that enables phishing attacksparentComments−kevincox2yVerifies what? That the preview matches? What if it changed between the send and the click legitimately? Also what is the threat model here? If the sender controls the URL they can generate any preview that they want.
Comments
Verifies what? That the preview matches? What if it changed between the send and the click legitimately? Also what is the threat model here? If the sender controls the URL they can generate any preview that they want.