Link with target=”_blank” and rel=”noopener noreferrer” still vulnerable?

You may be misunderstanding the vulnerability. You can read more about it here: https://www.jitbit.com/alexblog/256-targetblank—the-most-underestimated-vulnerability-ever/

Essentially, adding rel="noopener noreferrer" to links protects your site’s users against having the site you’ve linked to potentially hijacking the browser (via rogue JS).

You’re asking about removing that attribute via Developer Tools – that would only potentially expose you (the person tampering with the attribute) to the vulnerability.

Leave a Comment