Adobe last week issued a critical update for its Flash multimedia player, including a fix for a dangerous class of vulnerabilities that gives an attacker the ability to trick a user into clicking on something only barely or momentarily noticeable. The Flash patch addresses at least five security vulnerabilities, including two flaws that allow what’s being called “clickjacking,” a vulnerability present in Flash as well as multiple Web browsers that could allow an attacker to lure a user into unknowingly clicking on a link or dialog box, even if that link or box were located on another Web page. Clickjacking uses a technology known as “iFrames,” to invisibly load content from a separate Web page within the context of the page the user is viewing. Using a specially-crafted iFrame, a malicious site could load an invisible image that contains a URL from another page and overlay it transparently on top