CWE-1021: Improper Restriction of Rendered UI Layers or Frames

What is CWE-1021?

A web application fails to restrict, or incorrectly restricts, frames or user interface layers that belong to another application or domain.

Data statistics

OWASP TOP 10:2025 RANK6 — A06:2025 — Insecure Design
RELATED CVES (365 DAYS)28
ABSTRACTIONBase

Vulnerabilities mapped to CWE-1021

28 vulnerabilities211.1% increase year over year

Vulnerabilities in CISA KEV for CWE-1021

0 vulnerabilities

Official definition

ByMitre CWE

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

Detailed description

The weakness occurs when content can be rendered within, over, or alongside a user interface from another application or domain without adequate restrictions. An attacker can use this behavior to disguise the location or purpose of a control and induce a user to interact with an unintended underlying application. The issue is commonly associated with clickjacking and UI redress attacks; the comparable mobile scenario is often called tapjacking, where the user taps a manipulated interface.

Characteristics

This is an implementation-phase weakness affecting web-based applications and is not specific to a programming language or technology. Its defining behavior is the failure to enforce which external applications or domains may frame or otherwise render the application, including through frames, overlays, or related embedding elements. The record also identifies clickjacking, UI redress attack, and tapjacking as associated terms, with tapjacking referring to touch-based interaction in mobile applications.

Common consequences

The primary impact is on access control. By causing a user to activate concealed or misleading controls, an attacker may help gain privileges or assume an identity, bypass a protection mechanism, read application data, or modify application data. The specific result depends on the functionality exposed by the underlying application, such as changing privacy settings in a social media application.

ImpactScopeExplanation
Gain Privileges or Assume Identity, Bypass Protection Mechanism, Read Application Data, Modify Application DataAccess ControlAn attacker can trick a user into performing actions that are masked and hidden from the user's view. The impact varies widely, depending on the functionality of the underlying application. For example, in a social media application, clickjacking could be used to trick the user into changing privacy settings.

Risk mitigations

Apply layered restrictions during implementation:

  • Use X-Frame-Options to specify which domains may frame the application, while accounting for limitations and implementation gaps, including requirements to allow multiple domains.
  • For legacy browsers that do not support X-Frame-Options, use a frame-breaker script on pages that should not be framed. This is not sufficient by itself because frame-breaking scripts can be bypassed and may not correctly handle multiple nested frames.
  • As defense in depth, use Content Security Policy restrictions. Depending on the policy implementation, apply the frame-ancestors or frame-src directive to control permitted embedded content.
  • Restrict whether the application may be rendered through object, embed, or applet elements, in addition to controlling frames and iframes.
  1. ImplementationThe use of X-Frame-Options allows developers of web content to restrict the usage of their application within the form of overlays, frames, or iFrames. The developer can indicate from which domains can frame the content. The concept of X-Frame-Options is well documented, but implementation of this protection mechanism is in development to cover gaps. There is a need for allowing frames from multiple domains.
  2. ImplementationA developer can use a "frame-breaker" script in each page that should not be framed. This is very helpful for legacy browsers that do not support X-Frame-Options security feature previously mentioned. It is also important to note that this tactic has been circumvented or bypassed. Improper usage of frames can persist in the web application through nested frames. The "frame-breaking" script does not intuitively account for multiple nested frames that can be presented to the user.
  3. ImplementationThis defense-in-depth technique can be used to prevent the improper usage of frames in web applications. It prioritizes the valid sources of data to be loaded into the application through the usage of declarative policies. Based on which implementation of Content Security Policy is in use, the developer should use the "frame-ancestors" directive or the "frame-src" directive to mitigate this weakness. Both directives allow for the placement of restrictions when it comes to allowing embedded content.
  4. ImplementationIn addition to frames or iframes as previously mentioned, the web application is expected to place restrictions on whether it is allowed to be rendered within objects, embed, or applet elements.

Detection methods

Automated static analysis, also known as Static Application Security Testing, can identify some instances without executing the application. It can model data flow and control flow in source or compiled code and search for vulnerable patterns connecting input sources to sinks that interact with external components or lower layers. The method is rated highly effective in the record, but the record describes it as capable of finding some instances rather than all instances.

MethodApproachEffectiveness
Automated Static AnalysisAutomated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)High

Representative vulnerabilities

The official record provides these representative examples, not an exhaustive list:

  • CVE-2017-7440: A desktop application's email preview feature allowed clickjacking through a crafted email message.
  • CVE-2017-5697: A hardware or firmware product had insufficient clickjacking protection in its web user interface.
  • CVE-2017-4015: A data-loss prevention product was vulnerable to clickjacking through an HTTP response header.
  • CVE-2016-2496: Tapjacking in a mobile operating system permission dialog enabled access to private storage through a partially overlapping window.
  • CVE-2015-1241: A web browser was affected by tapjacking involving page navigation and touch or gesture events.
  • CVE-2017-0492: A mobile operating system's system UI allowed a malicious application to create a full-screen UI overlay and gain privileges.
Sources (7)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan