I received a mail from a friend who I was playing together in a multiplayer game. And it had a link to phishing page which would ask to login to view the file that the sent me. And my antivirus found it as a threat. I inspected the page it is a perfect template for phishing scam.
I want know when I am logged inside Gmail and if I click a link is there some way to access Gmail session data containing my authentication details using JavaScript even if I didn't do anything other than click on the link.