Reverse tabnabbing

Opener protection for links that open a new tab

Description

A newly opened page that can access window.opener may redirect the original tab to a phishing page. The current HTML standard and supporting browsers apply noopener behavior to target="_blank" by default. Missing explicit protection therefore does not by itself establish a vulnerability; check older environments and any explicit permission to retain an opener.

Potential impact

  • Replacing the original tab with a phishing page can expose credentials or sensitive information.
  • Users may trust the attack page because it appears in a previously trusted tab.

Remediation

  • Explicitly set rel="noopener" on external links opened in a new tab. Add rel="noreferrer" when needed; it provides the same opener protection and also suppresses the Referer header.
  • Apply a shared external-link policy through frameworks or components where possible.

Examples

Before

html
<a href="https://example.org" target="_blank">외부 링크</a>

After

html
<a href="https://example.org" target="_blank" rel="noopener noreferrer">외부 링크</a>

Explanation:

  • Before: Protection is not explicit. In environments that retain window.opener without the current default protection, the new page may redirect the original tab.
  • After: rel="noopener noreferrer" explicitly prevents the opener connection and Referer transmission on the target="_blank" link.

References