A browser feature I wasn't aware of for too long: long press the back button, to get a list of recent URLs, allowing you to skip anything trying to hijack the back button.

That’s surely bounded now much it can show, so an attacker can just fill it up till the api throws an error

Surely the browser could enforce a limit on a domain, and make sure that the real page you came from (typically the search engine) is prominently displayed.

[deleted]

Or right click