Earlier quoted context omitted.
Side note: click-to-play is a usability feature, not a security feature. It's still possible for Flash code to run before the user "clicks to play".
Click-to-play in Firefox at least is a security feature. It's enabled automatically for known-insecure plugins like old versions of Java and Flash. You can enable it manually by setting a plugin to "Ask to activate" in the Firefox add-on manager: https://blog.mozilla.org/security/2012/10/11/click-to-play-p... Click-to-play prevents Firefox from running any plugin code without explicit user action. I am 99% certain th…
Wrong: https://code.google.com/p/chromium/issues/detail?id=174963