Debunking native in-browser spell-jacking