Adobe Flash used to be a crowd favorite when it comes to exploiting web browsers with over 20 0day attacks using Flash vulnerabilities caught in the wild during the last 5 years. As a consequence of this trend and Flash's eventual deprecation, major web browsers don't play Flash content by default any more and now require user interaction in order to play it, aka click2play. This means that an attacker sitting on a stockpile of unpatched Flash vulnerabilities now needs a click2play bypass for those vulnerabilities to become relevant again.In this talk we will dive into the good, the bad and the ugly of click2play implementations in two major web browsers (Google Chrome and Microsoft Edge). I will show how I discovered several weaknesses in those implementations, including a full click2play bypass in Microsoft Edge.