Description
A newly opened page that can access window.opener may redirect the original tab to a phishing page. The current HTML standard and supporting browsers apply noopener behavior to target="_blank" by default. Missing explicit protection therefore does not by itself establish a vulnerability; check older environments and any explicit permission to retain an opener.
Potential impact
- Replacing the original tab with a phishing page can expose credentials or sensitive information.
- Users may trust the attack page because it appears in a previously trusted tab.
Remediation
- Explicitly set
rel="noopener"on external links opened in a new tab. Addrel="noreferrer"when needed; it provides the same opener protection and also suppresses the Referer header. - Apply a shared external-link policy through frameworks or components where possible.
Examples
Before
html
<a href="https://example.org" target="_blank">외부 링크</a>
After
html
<a href="https://example.org" target="_blank" rel="noopener noreferrer">외부 링크</a>
Explanation:
- Before: Protection is not explicit. In environments that retain
window.openerwithout the current default protection, the new page may redirect the original tab. - After:
rel="noopener noreferrer"explicitly prevents the opener connection and Referer transmission on thetarget="_blank"link.