-
@simevidas WCO (web.dev/window-controls-overlay/) lets the disguise become even more perfect. Another attack vector is to start like a harmless PWA that then tries to change its identity to look like your banking software. This is why WCO is opt-in and icon and/or name changes will require a prompt.