htmlsecurityiframe

Why are iframes considered dangerous and a security risk?


Why are iframes considered dangerous and a security risk? Can someone describe an example of a case where it can be used maliciously?


Solution

  • As soon as you're displaying content from another domain, you're basically trusting that domain not to serve-up malware.

    There's nothing wrong with iframes per se. If you control the content of the iframe, they're perfectly safe.