So forgive my ignorance, but this would only be an issue if links can be placed on your site by others, where they also can embed javascript as part of the link, yes?
EDIT -
I mean aside from cases where you're intentionally using this on your site for unscrupulous reasons.
If you link to my site with target="_blank" and without rel="noopener" or some other preventative measure, that's all that needs to happen. The JavaScript is run on the other person's website. So all you have to do is link to their site and they get access to the location of the tab of the original site. No XSS or anything needed.
The risk is real. When some site has a link with _blank to your site, the opener site stays accessible for javascript code that is embedded in your site.