Clickjacking Attack on Facebook | Netsparker

There are two important points to remember with X-Frame-Options: Chromium based browsers only partially support X-Frame-Options (the ALLOW-FROM directive is unavailable) Using the ALLOW-FROM URL instruction, we can whitelist only one domain and allow our website to be loaded in an iframe. Important Points About the X-Frame-Options HTTP Header

https://www.netsparker.com/blog/web-security/clickjacking-attack-on-facebook-how-tiny-attribute-save-corporation/